← Back

Wire · founder news, decoded · regulatory

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

Published

23 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

United States

Source

Read at cyberscoop.com

Verified

Fusion42 · 23 July 2026 · Fusion42 review

Russian state-sponsored group Laundry Bear exploited a zero-day vulnerability in Zimbra Collaboration Suite for five months before patching in November 2025, stealing email, credentials, and authentication tokens from governments and organisations across defence, energy, finance and technology sectors. The group continues active exploitation of unpatched instances.

This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

The Wire takeaway

If your product or service sits between users and Zimbra, or you rely on Zimbra for customer data, Russian intelligence now has five months' worth of a way into your infrastructure—and unpatched instances are still bleeding. Patch immediately and assume breach; credential rotation and account review are not optional.

Related on Wire

Topics

Cybersecurity · zero-day-vulnerability · email-compromise · russian-espionage · zimbra-exploit · credential-theft · multi-sector