Dossier
CVE-2025-66376
Coverage of CVE-2025-66376 in the Nexus archive.
- Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
A Russian state-sponsored threat group, Laundry Bear (also known as Void Blizzard), has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite since July 2025 to steal sensitive data from governments and organizations in sectors like defense, education, and technology. The exploit, patched in November 2025, allows attackers to steal emails, passwords, and other data without user interaction, as reported in a joint cybersecurity advisory by U.S. authorities and international partners.