A joint advisory from US agencies, including the Cybersecurity and Infrastructure Security Agency and the National Security Agency, warns that the Russian-linked APT group Laundry Bear is actively exploiting a patched vulnerability in Zimbra Collaboration servers to steal email accounts. The attackers are targeting organizations that have not applied the necessary patch for CVE-2025-66376, a cross-site scripting flaw that allows malicious JavaScript code execution. This vulnerability enables Laundry Bear to gain unauthorized access to sensitive email accounts, posing a significant threat to organizations using unpatched Zimbra servers. The advisory emphasizes the importance of promptly applying the patch to prevent exploitation1. This warning matters to security practitioners because the exploitation status of CVE-2025-66376 determines whether this is a patch-now or monitor situation, highlighting the need for prompt action to prevent potential breaches.
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
⚡ High Priority
Why This Matters
CVE-2025-66376 is in active discussion involving NSA — exploitation status determines whether this is patch-now or monitor.
References
- SecurityAffairs. (2026, July 24). US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers. SecurityAffairs. https://securityaffairs.com/195901/apt/us-agencies-warn-of-laundry-bear-campaign-targeting-unpatched-zimbra-servers.html
Original Source
SecurityAffairs
Read original →