"The Laundry Bear campaign exploits a zero-day vulnerability in ZCS (CVE-2025-66376) which was publicly disclosed in November 2025 and uses a zero-click exploit coined 'beehive' to steal emails and other sensitive data."
CVE-2025-66376 and the 'beehive' zero-click exploit
The advisory released on July 23 describes a view-based, zero-click attack that leverages a vulnerability tracked as CVE-2025-66376 in the Zimbra Collaboration Suite (ZCS). The operation uses what the agencies call a "beehive" exploit: an email that only needs to be viewed — not clicked or opened in the conventional sense — within a vulnerable webmail instance to trigger compromise. If the exploit succeeds, attackers attempt to exfiltrate at least the last 90 days of emails and other sensitive information from the mail server.
Attribution: Laundry Bear (Void Blizzard, UAC-0190) and the international advisory
The campaign has been attributed by the alert to a Russian state-supported cyber espionage operation known as Laundry Bear, also tracked as Void Blizzard and UAC-0190. The joint advisory was issued by the UK National Cyber Security Centre together with multiple U.S. agencies — the Cybersecurity and Infrastructure Security Agency, the National Security Agency and the FBI — and cyber and intelligence agencies from Canada, Australia and New Zealand, plus unnamed European agencies.
Scope of targets and techniques to maintain access
According to the advisory, targeted and compromised organizations include entities across defense, government, education, energy, law enforcement, media, NGOs and technology sectors. Beyond bulk email theft, the attackers seek persistence: the operation attempts to steal passwords and to circumvent multi-factor authentication protections by abusing session tokens. The advisory notes that the campaign has been active against ZCS installations since at least July 2025, with the CVE later disclosed publicly in November 2025.
Defensive steps: patching, monitoring and passkeys
Authorities urged organizations using ZCS to take immediate action. The advisory's technical recommendations include installing patches for the critical vulnerabilities and enhancing network monitoring to detect suspicious activity. System administrators were specifically advised to be on the lookout for indicators of compromise and anomalous behavior. The advisory also recommends considering a third-party authentication service that supports passkeys to mediate access to ZCS and services that lack native passkey support; agencies said this can reduce the risk that stolen credentials will be leveraged to reach servers.
How technologists, affected enterprises, and policymakers are responding
- Technologists and security teams: will prioritize patch management and heightened monitoring of mail servers running ZCS, and look for signs of session-token abuse and password exfiltration as described in the advisory.
- Affected enterprises and system administrators: have been told to apply critical patches immediately and to consider third-party authentication services that support passkeys to limit credential-stuffing or session token misuse.
- Policymakers and national cyber-defence authorities: coordinated the joint advisory across the UK, U.S., Five Eyes partners and European agencies — signaling cross-border concern and shared technical guidance on mitigation.
The advisory also raised a secondary technical point: "technical analysis of the campaign indicated that AI played a role in the development of a simple codebase for the operation." Agencies used that finding to underline how malicious actors may adapt automation and emerging tools to scale or simplify offensive tooling.
"This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations," said Beth Hopkins, COO of the NCSC. "With our international partners, we strongly encourage organizations to familiarize themselves with the 'zero-click' techniques described in the advisory which could be used against other platforms, and act on the mitigation advice."
The immediate, concrete task for defenders is clear in the advisory: patch ZCS, increase monitoring for the specific tactics described, and consider passkey-capable authentication gateways where possible. The darker, persistent question the notice leaves on the table is whether other widely used mail and collaboration platforms may harbor similar, view-triggered failures that could let attackers repeat the "beehive" pattern. For organizations that rely on Zimbra today, acting on the advisory is not optional — it is the frontline against theft of months of communications and the longer-term loss of account control.
https://www.infosecurity-magazine.com/news/russian-hackers-zero-click/




