Vulnerabilities · 67 days ago
Zimbra Patches Linger While Mailboxes Stay Readable The break is not the XSS alone. It is that patched Zimbra servers still left mail readable long after disclosure, so viewing an email can keep handing over account data, directory data, and session access after the fix is out. That makes old mailboxes part of the incident, not just the server.
CISA and partner agencies say Laundry Bear kept using CVE-2025-66376 after Zimbra patched it, against government and commercial targets across defense, education, energy, legal, media, technology, and other critical sectors. The same advisory says the exploit fires when a malicious email is rendered in Zimbra’s Classic UI, so no click is needed, and the group has used the access to take recent mail, addresses, passwords, 2FA tokens, and new app passcodes.
A separate UAC-0099 Notepad++ plugin campaign is bundled in the reporting, but it is a different triage path. The Zimbra story is the one that changes the threat model: patching the server does not undo mailbox exposure, and stolen session material can keep the compromise alive.
NVD KEV
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).
CISA federal remediation date Apr 1 · date passed
Timeline Sources 13 sources covering this story
Help Net Security Jul 24
Russian hackers exploit unpatched Zimbra servers to steal emails - Help Net Security
Laundry Bear exploited a Zimbra Collaboration Suite vulnerability in phishing attacks targeting governments and critical sectors worldwide.
The Hacker News Jul 24
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every three minutes on Windows.
Risky Biz News Jul 24
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
A Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and [Read More
Dark Reading Jul 23
Russian Hackers Exploit Zimbra 0-Day Against US, Ukraine Targets
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
The Hacker News Jul 23
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian spies exploited CVE-2025-66376 in Zimbra to steal 90 days of mail, passwords, 2FA codes, and directories from Western targets.
CyberScoop Jul 23
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
and allied officials warn of Russian espionage group Laundry Bear exploiting a Zimbra zero-day vulnerability to steal sensitive email data.
The Record from Recorded Future Jul 23
International alert spotlights Russia-linked attacks on Zimbra webmail
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S.
Proofpoint Jul 23
International alert spotlights Russia-linked attacks on Zimbra webmail
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S.
Infosecurity Magazine Jul 23
Russian Hackers Exploit New ‘Zero-Click’ Attack
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite
Unit 42 Jul 23
Russian Global Webmail Espionage
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials.
BleepingComputer Jul 23
Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.
BleepingComputer Jul 23
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
Entities CVE-2025-66376 Laundry Bear UAC-0099 Part of the PlainSec briefing for 2026-07-23
Editions Related stories
Vulnerabilities · 67 days ago
Zimbra Patches Linger While Mailboxes Stay Readable The break is not the XSS alone. It is that patched Zimbra servers still left mail readable long after disclosure, so viewing an email can keep handing over account data, directory data, and session access after the fix is out. That makes old mailboxes part of the incident, not just the server.
CISA and partner agencies say Laundry Bear kept using CVE-2025-66376 after Zimbra patched it, against government and commercial targets across defense, education, energy, legal, media, technology, and other critical sectors. The same advisory says the exploit fires when a malicious email is rendered in Zimbra’s Classic UI, so no click is needed, and the group has used the access to take recent mail, addresses, passwords, 2FA tokens, and new app passcodes.
A separate UAC-0099 Notepad++ plugin campaign is bundled in the reporting, but it is a different triage path. The Zimbra story is the one that changes the threat model: patching the server does not undo mailbox exposure, and stolen session material can keep the compromise alive.
NVD KEV
Known exploited · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97th percentile).
CISA federal remediation date Apr 1 · date passed
Timeline Sources 13 sources covering this story
Help Net Security Jul 24
Russian hackers exploit unpatched Zimbra servers to steal emails - Help Net Security
Laundry Bear exploited a Zimbra Collaboration Suite vulnerability in phishing attacks targeting governments and critical sectors worldwide.
The Hacker News Jul 24
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every three minutes on Windows.
Risky Biz News Jul 24
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
A Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and [Read More
Dark Reading Jul 23
Russian Hackers Exploit Zimbra 0-Day Against US, Ukraine Targets
A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
The Hacker News Jul 23
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Russian spies exploited CVE-2025-66376 in Zimbra to steal 90 days of mail, passwords, 2FA codes, and directories from Western targets.
CyberScoop Jul 23
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
and allied officials warn of Russian espionage group Laundry Bear exploiting a Zimbra zero-day vulnerability to steal sensitive email data.
The Record from Recorded Future Jul 23
International alert spotlights Russia-linked attacks on Zimbra webmail
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S.
Proofpoint Jul 23
International alert spotlights Russia-linked attacks on Zimbra webmail
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S.
Infosecurity Magazine Jul 23
Russian Hackers Exploit New ‘Zero-Click’ Attack
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite
Unit 42 Jul 23
Russian Global Webmail Espionage
Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials.
BleepingComputer Jul 23
Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.
BleepingComputer Jul 23
Hackers abuse Notepad++ plugins to stealthily install malware
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
Entities CVE-2025-66376 Laundry Bear UAC-0099 Part of the PlainSec briefing for 2026-07-23
Editions Related stories