Wire · founder news, decoded · regulatory
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
◆ Published
23 July 2026
◆ Topic
regulatory
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 23 July 2026 · Fusion42 review
Russian state-sponsored group Laundry Bear exploited a zero-day vulnerability in Zimbra Collaboration Suite for five months before patching in November 2025, stealing email, credentials, and authentication tokens from governments and organisations across defence, energy, finance and technology sectors. The group continues active exploitation of unpatched instances.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If your product or service sits between users and Zimbra, or you rely on Zimbra for customer data, Russian intelligence now has five months' worth of a way into your infrastructure—and unpatched instances are still bleeding. Patch immediately and assume breach; credential rotation and account review are not optional.
◆ Related on Wire
- CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian ...23 July 2026
- Russian hackers can steal government emails without victims clicking a link, cyber agencies warn23 July 2026
- US Imposes Sanctions on Belarusian Man in Ransomware Case14 July 2026
- US charges Russian 'bulletproof' web hosts over cyberattacks that netted $62M from ...15 July 2026
- US authorities warn that state-linked hackers are targeting vulnerable networking devices14 July 2026
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV17 July 2026
◆ Topics
Cybersecurity · zero-day-vulnerability · email-compromise · russian-espionage · zimbra-exploit · credential-theft · multi-sector