← Back

Wire · founder news, decoded · regulatory

CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian ...

Published

23 July 2026

Topic

regulatory

Geography

United States

Source

Read at cisa.gov

Verified

Fusion42 · 23 July 2026 · Fusion42 review

Russian state-backed APT group LAUNDRY BEAR is conducting a zero-click phishing campaign against Zimbra Collaboration Suite users across Western government and commercial organisations, exploiting CVE-2025-66376 to exfiltrate email credentials and 2FA tokens. CISA, NSA, FBI and international partners have published mitigations and remediation guidance for organisations using ZCS webmail.

The Wire takeaway

If you sell email security, backup, or identity verification to government or defence contractors, your customers are being actively hunted right now and will buy hardening. If you run Zimbra, patch CVE-2025-66376 this week—LAUNDRY BEAR's toolkit works without user interaction.

Related on Wire

Topics

zero-day-exploit · email-security · nation-state-threat · critical-infrastructure · credential-theft