Wire · founder news, decoded · regulatory
CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian ...
◆ Published
23 July 2026
◆ Topic
regulatory
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 23 July 2026 · Fusion42 review
Russian state-backed APT group LAUNDRY BEAR is conducting a zero-click phishing campaign against Zimbra Collaboration Suite users across Western government and commercial organisations, exploiting CVE-2025-66376 to exfiltrate email credentials and 2FA tokens. CISA, NSA, FBI and international partners have published mitigations and remediation guidance for organisations using ZCS webmail.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you sell email security, backup, or identity verification to government or defence contractors, your customers are being actively hunted right now and will buy hardening. If you run Zimbra, patch CVE-2025-66376 this week—LAUNDRY BEAR's toolkit works without user interaction.
◆ Related on Wire
- Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries23 July 2026
- Russian hackers can steal government emails without victims clicking a link, cyber agencies warn23 July 2026
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV17 July 2026
- CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild23 July 2026
- US authorities warn that state-linked hackers are targeting vulnerable networking devices14 July 2026
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days13 July 2026
◆ Topics
Cybersecurity · zero-day-exploit · email-security · nation-state-threat · critical-infrastructure · credential-theft