Storyline
Russian group exploits Zimbra email zero-day
Russian state-sponsored threat group Laundry Bear (also known as Void Blizzard) has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite since July 2025 to steal emails, credentials, and two-factor authentication codes from government and organizational targets in Western countries. CISA has warned of the attacks and the vulnerability has since been patched.
This is a long-running storyline that has developed over 14 days. The homepage highlights its most recent activity, so the outlet count there reflects the latest wave. The totals above cover the full run.
Laundry BearVoid BlizzardZimbra Collaboration SuiteCISARussian state-sponsored group