Skip to content
The Nexus
SECURITYJul 23 · 17:33 UTCCYBERSCOOPMatt Kapko

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

A Russian state-sponsored threat group, Laundry Bear (also known as Void Blizzard), has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite since July 2025 to steal sensitive data from governments and organizations in sectors like defense, education, and technology. The exploit, patched in November 2025, allows attackers to steal emails, passwords, and other data without user interaction, as reported in a joint cybersecurity advisory by U.S. authorities and international partners.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries · The Nexus