Skip to content
The Nexus
Storyline10 outlets17 articlesFirst Jul 23 · 17:33 UTCLatest Aug 6 · 06:07 UTC

Russian group exploits Zimbra email zero-day

Russian state-sponsored threat group Laundry Bear (also known as Void Blizzard) has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite since July 2025 to steal emails, credentials, and two-factor authentication codes from government and organizational targets in Western countries. CISA has warned of the attacks and the vulnerability has since been patched.

This is a long-running storyline that has developed over 14 days. The homepage highlights its most recent activity, so the outlet count there reflects the latest wave. The totals above cover the full run.

Forward this
Key entities
Laundry BearVoid BlizzardZimbra Collaboration SuiteCISARussian state-sponsored group
Volume · 15 days · 17 articlesPeak: 3 on 2026-08-03
2026-07-232026-08-06
Articles in this storyline

2026-08-06

1 article · 1 outlet
CoinTelegraph

2026-08-05

1 article · 1 outlet
Moscow Times

2026-08-04

2 articles · 2 outlets
Recorded Future NewsKyiv Post

2026-08-03

3 articles · 3 outlets
Bleeping ComputerKyiv PostDeutsche Welle

2026-08-02

1 article · 1 outlet
Kyiv Post

2026-07-31

1 article · 1 outlet
The Hacker News

2026-07-30

1 article · 1 outlet
The Hacker News

2026-07-29

2 articles · 2 outlets
Bleeping ComputerRecorded Future News

2026-07-27

1 article · 1 outlet
Daily Mail

2026-07-25

1 article · 1 outlet
Kyiv Post