A Russian state-sponsored threat group, known as Laundry Bear, has been leveraging a novel exploit in the Zimbra Collaboration Suite to steal sensitive data from Western countries since July 2025. The group's exploitation of a zero-day vulnerability in the Linux-based enterprise software allowed them to gain unauthorized access to systems, with the vulnerability remaining unpatched until November 2025. This five-month window enabled the threat actors to conduct extensive espionage campaigns, targeting governments and commercial organizations. The exploit requires minimal interaction, making it a significant concern for organizations using the Zimbra software. Laundry Bear's activities highlight the importance of prompt patching and vulnerability management, as the window for remediation is rapidly closing1. This campaign's success underscores the need for organizations to assess their exposure to such threats immediately, as the consequences of delayed action can be severe.