Skip to main content

Tag: cve 2025 66376

3 articles

Government agency office with computer workstations and people in the background.

Kremlin Hackers Exploit Zimbra Bug to Infiltrate Networks

Kremlin hackers, also known as Laundry Bear, have been exploiting a vulnerability in the Zimbra Collaboration Suite to secretly infiltrate government and commercial networks for over a year, aiming to gather sensitive information for the Russian Federation. They've been using malicious emails to inject JavaScript code, allowing them to covertly acquire email data.

Analyst 207
Government officials gather in a secure briefing room with a computer screen visible in the background.

Russian Hackers Exploit Zimbra Flaw for Widespread Email Theft

Russian hackers have exploited a Zimbra flaw, CVE-2025-66376, to steal emails from targeted organizations, allowing them to automatically collect a victim's last 90 days of email without requiring any interaction. This alarming vulnerability was weaponized by the Russian state-sponsored group Laundry Bear using a combination of phishing and specially crafted HTML emails.

Analyst 207
Rows of computer servers and network equipment in a brightly-lit corporate network operations center.

Russian Hackers Exploit Zero-Click Attack on Western Organizations

Russian hackers have launched a stealthy zero-click attack, dubbed "beehive," targeting Western organizations by exploiting a vulnerability in the Zimbra Collaboration Suite, allowing them to siphon off sensitive emails and data with just a viewed email. This alarming threat highlights the need for organizations to bolster their defenses against such sophisticated cyber threats.

Analyst 207