THREAT INTELLIGENCE CYBERTTAKv3.0.3.0
LIVE FEED ACTIVE
← Back to Intel Feed
Secure route: /intel/ai-russian-state-supported-cyber-actors-targeting-zimbra-collaboration-suite-via-zero-day-exploit-a7619d45
criticalCVE-2025-663762026-07-23Vector: appsec

Russian State-Supported Cyber Actors Targeting Zimbra Collaboration Suite via Zero-Day Exploit

A Russian-backed hacking group known as LAUNDRY BEAR is exploiting a vulnerability in Zimbra email software to secretly steal emails and sensitive account information from government and business organizations.

Decision Context

English Brief

A Russian-backed hacking group known as LAUNDRY BEAR is exploiting a vulnerability in Zimbra email software to secretly steal emails and sensitive account information from government and business organizations.

الموجز العربي

جهات سيبرانية مدعومة من روسيا تستهدف برمجيات Zimbra عبر ثغرة يوم الصفر

تقوم مجموعة قرصنة مدعومة من روسيا تُعرف باسم "LAUNDRY BEAR" باستغلال ثغرة في برمجيات البريد الإلكتروني "Zimbra" لسرقة رسائل البريد الإلكتروني ومعلومات الحسابات الحساسة سراً من المؤسسات الحكومية والتجارية.

Affected Products
    Priority sectors
    Defense Industrial BaseGovernmentEducationEnergyLaw EnforcementMediaNon-governmental OrganizationsTechnology
    Immediate Actions
    1. 1Apply patches immediately: Update all ZCS instances to the latest version.
    2. 2Audit logs for suspicious application passcodes created via API.
    3. 3Rotate credentials for any user account with recent anomalous login patterns.