Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Zimbra preview leaks mail to Russia

2 min read
12:09UTC

CISA, the NSA and the FBI named Russian actor LAUNDRY BEAR behind a zero-click Zimbra flaw that reads 90 days of mail on a single preview, in an advisory fifteen agencies co-sealed.

TechnologyAssessed
Key takeaway

Fifteen nations named a Russian zero-click Zimbra exploit that fires on preview, beyond any awareness training.

CISA, the National Security Agency (NSA) and the FBI published joint advisory AA26-204A on Thursday 23 July, co-sealed by fifteen partner agencies including Britain's NCSC, France's ANSSI and the Dutch AIVD, naming Russian state-supported actor LAUNDRY BEAR behind a zero-click exploit of Zimbra Collaboration Suite (ZCS) webmail 1.

Merely viewing a single email hands the actor the victim's last 90 days of mail and the organisation's Global Address List (GAL), the internal directory of every staff name and address. The chain abuses CVE-2025-66376, a common vulnerabilities and exposures (CVE) flaw Zimbra patched in November 2025, so every still-exposed appliance has run eight months unpatched.

LAUNDRY BEAR, tracked elsewhere as Void Blizzard and CL-STA-1114, drew a Dutch intelligence attribution in May 2025 for password-spraying and pass-the-cookie theft against cloud email. The exploit now fires the moment a target previews the message, removing the human-error step that awareness training targets. The advisory warns it will pivot to other webmail platforms as ZCS patching climbs, so fixing the appliance closes only today's door.

Fifteen co-sealing agencies is an unusually broad coalition; the FSB Centre 16 router-hijacking advisory two weeks earlier carried eighteen , against the two to four names a routine attribution once bore. The advisory format is scaling to match the breadth of Western email systems inside the blast radius.

Deep Analysis

In plain English

Zimbra Collaboration Suite is email software that organisations run on their own servers instead of using a service like Gmail. A flaw in it, tracked as CVE-2025-66376, let attackers read someone's email just by having it appear in their inbox, without the victim clicking anything. A hacking group Western governments call LAUNDRY BEAR, working on behalf of Russia, used this flaw to read and copy emails from targets for up to three months at a time. On 23 July, 15 countries led by the US cyber agency CISA, the NSA and the FBI jointly published a warning naming LAUNDRY BEAR and explaining how the attack worked, so organisations still running unpatched Zimbra servers know to fix them immediately.

Deep Analysis
Root Causes

The zero-click chain depended on Zimbra's self-hosted deployment model: unlike SaaS webmail, patching CVE-2025-66376 required each organisation's own IT team to apply the fix, and CISA's figures show many did not for eight months after it shipped.

A second structural gap is verification lag: zero-click delivery meant victims had no phishing click or malicious attachment to alert defenders, so mail exfiltration could run for up to 90 days before detection tools built for user-triggered compromise caught the activity.

Escalation

The 15-agency signature count is itself an escalation signal: joint advisories of this scale are reserved for actors governments want publicly deterred, not merely technically documented.

What could happen next?
  • Meaning

    A 15-agency joint attribution list signals Western governments shifting toward public, coordinated naming of Russian state-linked actors rather than quiet technical warnings.

  • Risk

    Organisations still running unpatched Zimbra Collaboration Suite deployments remain exposed to the same zero-click chain until they apply the CVE-2025-66376 fix.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

CISA· 24 Jul 2026
Read original
Causes and effects
This Event
Zimbra preview leaks mail to Russia
A preview-triggered exploit removes the user-error step defensive training relies on, leaving patch speed on the webmail appliance as the only working control.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.