NSA, CISA Warn Russian Hackers Stole 90 Days of Mail via Zimbra Zero-Day
Updated
Updated · The Hacker News · Jul 24
NSA, CISA Warn Russian Hackers Stole 90 Days of Mail via Zimbra Zero-Day
3 articles · Updated · The Hacker News · Jul 24
Summary
A joint NSA-CISA advisory said a Russian state-backed group exploited Zimbra flaw CVE-2025-66376 since at least July 2025, compromising Western government and commercial mailboxes by getting users to merely view a malicious email.
The stored XSS bug in Zimbra Classic UI let the payload run inside authenticated sessions, steal 90 days of email, browser-saved passwords, 2FA recovery codes and the full address list, then exfiltrate data over DNS.
Zimbra patched affected versions on Nov. 6, 2025—10.0 before 10.0.18 and 10.1 before 10.1.13—but agencies warned patching alone does not revoke stolen credentials or app-specific passwords that can survive password resets.
Proofpoint said the group, tracked as TA488, used the zero-day for at least 5 months in 2025 and has not seen activity since February 2026, while Unit 42 said attackers are still actively targeting unpatched Zimbra servers.
The campaign targeted sectors including government, defense, transportation and finance across NATO states, Ukraine, the CIS and Africa, underscoring that account cleanup now matters as much as upgrading to supported Zimbra 10.1 releases.
How did a single hidden code in a viewed email silently compromise Western defense networks for months before detection?
Where did the Russian cyber espionage group pivot their silent attacks after vanishing from the radar in early 2026?
Russian APT28 Exploits Zimbra Zero-Day: 10,500+ Servers at Risk in Ongoing Global Espionage Wave (2025–2026)
Overview
The report details how Russian APT group LAUNDRY BEAR exploited a zero-day vulnerability in Zimbra email servers, starting in July 2025, to access Western mailboxes undetected. Even after patches were released, many servers remained unpatched, allowing attackers to adapt their tactics and use compromised accounts for stealthy phishing. The attack bypassed Zimbra’s HTML sanitizer, enabling malicious code to execute automatically in users’ browsers. This code harvested credentials, created persistent access, and exfiltrated data via DNS and HTTPS. Remediation is complex, as upgrading Zimbra often requires simultaneous operating system migrations, causing significant operational and security challenges for organizations.