Russian hackers stole emails from users of the widely used Zimbra email server using a previously unknown exploit that didn’t require users to click on a link or open an attachment, said officials in the US, UK and allied countries.
The issue, tracked as CVE-2025-66376, which has now been patched, has been exploited since July of last year by a threat group tracked as Laundry Bear and is being used in ongoing attacks on servers that haven’t been updated to apply the patch, authorities said.
Image credit: Fotolia
Zero-day exploit
The threat group uses a custom capability called Ulej to try to steal an organisation’s email directory, the last 90 days of a victim’s communications, and other sensitive data.










