A Russia-backed group exploited a Zimbra Collaboration Suite flaw for months before the vulnerability became public, US authorities said Thursday. The group, known as Laundry Bear, could obtain as much as 90 days of a user's email, address-book data and other information, and could establish persistent access. [1] [2]
The phrase zero-day captures the period when defenders lacked a publicly disclosed vulnerability record. It does not capture what an attacker could learn from three months of correspondence. A mailbox can contain contracts, travel, internal disputes, reset links, contact networks and the sequence of decisions that makes the next operation easier.
Cybersecurity Dive reported that Laundry Bear first targeted cloud environments in Ukraine and then expanded toward Western government and private organizations in industrial sectors. The campaign initially focused on Microsoft Exchange environments before using CVE-2025-66376 against Zimbra beginning around May 2025. The vulnerability was not published until January 2026. [1]
CISA and the National Security Agency connect the actor, campaign, vulnerability, capability and mitigation in a federal advisory. [2] That is a stronger evidence stage than an anonymous threat claim. It is still not a complete account of who was compromised, which messages were taken, how long persistence survived or how stolen information was later used.
The technical weakness involved improper sanitization of cascading-style-sheet import directives, allowing a JavaScript payload to run. [1] The practical sequence is less exotic than the label suggests: a phishing message reaches a user, malicious content exploits the mail client, data leave the mailbox and the attacker seeks a durable foothold. Novel code opens the door; ordinary institutional correspondence supplies the value.
Authorities advised immediate patching and recommended moving to another email client when a patch could not be applied at once. [1] [2] That recommendation contains an operational choice often lost in breach coverage. An organization must weigh continued use, migration cost, compatibility, evidence preservation and the possibility that patching closes the flaw without removing established persistence.
The federal attribution should also remain bounded. Russia-backed identifies the government's assessment of the actor. It does not prove that every possible victim lost 90 days of mail or that every successful compromise produced persistent access. Capability is not a census. A final damage account requires organization-level logs, collection records, notification and independent technical corroboration.
The assignment's X search timed out. That retrieval failure supplies no platform reaction from defenders, victims or Russian accounts. The platform cannot be called silent, and no consensus about attribution or severity can be inferred from an unreturned search.
The useful public ledger would name sectors and countries without exposing vulnerable organizations prematurely. It would record compromise dates, patch status, persistence mechanism, data categories, notifications and downstream operations. It would also distinguish attempted phishing from code execution, code execution from extraction, and extraction from any later intelligence use.
Mail retention changes the possible exposure at each organization. An account holding a few days of messages presents a different collection opportunity from one containing years of archives, delegated mailboxes and reusable links. Administrators also need to inspect tokens, forwarding rules and connected cloud accounts, because a repaired client may leave a second route open.
Thursday's advisory makes a long campaign visible. [2] The zero-day ended when the flaw became public. The quieter problem did not necessarily end with publication: an organization can fix one vulnerable door while an intruder keeps a key made during the months when nobody knew to look.
-- DAVID CHEN, Beijing