A joint advisory from US agencies, including the Cybersecurity and Infrastructure Security Agency and the National Security Agency, warns that the Russian-linked APT group Laundry Bear is actively exploiting a patched vulnerability in Zimbra Collaboration servers to steal email accounts. The attackers are targeting organizations that have not applied the necessary patch for CVE-2025-66376, a cross-site scripting flaw that allows malicious JavaScript code execution. This vulnerability enables Laundry Bear to gain unauthorized access to sensitive email accounts, posing a significant threat to organizations using unpatched Zimbra servers. The advisory emphasizes the importance of promptly applying the patch to prevent exploitation1. This warning matters to security practitioners because the exploitation status of CVE-2025-66376 determines whether this is a patch-now or monitor situation, highlighting the need for prompt action to prevent potential breaches.