"The exploit just requires a view — no clicks — and allows attackers to steal the previous 90 days’ worth of email, the account’s password, search history, the victim organization’s email directory, two‑factor authentication tokens and other newly created passwords." Officials made that stark inventory in a joint cybersecurity advisory released by the United States and more than a dozen allies.
CVE-2025-66376 and the no‑click Zimbra exploit
U.S. authorities and cyber officials from Australia, Canada, New Zealand, the United Kingdom, Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, the Netherlands, Poland, Spain and Sweden warned that a previously unknown vulnerability — tracked as CVE-2025-66376 — in Zimbra Collaboration Suite was being exploited in a campaign that began in July 2025. The vulnerability was not patched until November 2025, five months after attacks were already active, the advisory said.
The advisory emphasized the unusual simplicity of the attack vector: the exploit requires only that a victim view a malicious message or content, not click a link or open an attachment. That no‑click characteristic enabled broad access to recent mailbox contents and authentication artifacts without the typical user interaction defenders expect to block.
Laundry Bear (Void Blizzard): espionage, not extortion
Officials attributed the campaign to Laundry Bear, also known as Void Blizzard, describing it as a Russian state‑sponsored threat group that has been active since at least 2024. The advisory noted the "covert and persistent nature" of the activity and the "absence of any known financial extortion," concluding those features "almost certainly indicate this group’s involvement in espionage activities with Russian government backing."
The advisory also observed a pattern of "extensive Ukrainian targeting, prior to use against U.S. and other NATO allies," saying that Ukrainian victims were used both as priority targets and, effectively, as a testbed for techniques later deployed elsewhere.
Beehive, custom JavaScript payloads, and how data was taken
Technical details in the advisory describe multiple capabilities. Laundry Bear delivered a custom JavaScript payload to targeted victims via phishing emails and used a novel data‑exfiltration and aggregation capability the advisory dubbed "beehive." The combined toolset could siphon mailbox contents going back 90 days, capture account passwords and newly created passwords, extract search history and the organization’s address directory, and harvest two‑factor authentication tokens.
Officials warned the group could adapt the beehive technique to exploit other software flaws, magnifying the long‑term risk if vulnerable systems remain exposed. The advisory also highlighted that the defect carried a medium severity rating of 6.1 — a detail officials used to underscore the practical difficulty organizations face in prioritizing patches based solely on severity scores.
Targets: Ukraine first, then Western governments and critical sectors
The advisory said Laundry Bear compromised governments and organizations across multiple sectors, including defense, education, energy, law enforcement, media, finance, transportation and technology. While officials did not identify specific victims or quantify the total number of compromises, they emphasized the campaign’s cross‑sector reach and persistent exploitation of unpatched Zimbra instances.
Authorities also noted that the group's "targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations" by finding public‑facing infrastructure and compiling email addresses to direct the phishing and no‑click exploit at selected users.
What technologists, policymakers, and affected organizations should watch
- Technologists and security teams: The advisory provided indicators of compromise and mitigation steps and urged organizations to update their vulnerable Zimbra software. Officials said instances that remain unpatched are still being actively exploited.
- Policymakers and regulators: The cross‑national advisory — spanning the United States and 15 other countries — signals coordinated attribution and response, focusing on espionage risks rather than financial crime and emphasizing the strategic sequencing of Ukrainian targeting.
- Affected enterprises and procurement leaders: The incident highlights a tradeoff called out by officials: a medium severity score (6.1) may not prompt rapid patching, yet the vulnerability enabled high‑impact data theft. Buyers and defenders must balance patch timing against exposure to targeted attackers who can weaponize even mid‑severity defects.
Authorities closed their advisory by sharing technical indicators, mitigation steps and a clear instruction: update vulnerable Zimbra instances. With Laundry Bear described as "still actively exploiting Zimbra Collaboration Suite instances that remain unpatched," the factual consequence is immediate and limited: unpatched systems remain a live channel for espionage. Whether administrators act quickly enough to close that channel will determine, in practical terms, how much sensitive correspondence and authentication material ultimately remains at risk.




