discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Russian hackers exploit Zimbra zero-click flaw for email theft

Russian hackers, part of the Laundry Bear group, are exploiting a zero-click flaw in Zimbra email servers to steal user data. The flaw, patched in November 2025, allows attackers to steal emails, passwords, and 2FA tokens without requiring user interaction.

By Lawrence Abrams·Jul 23·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

Russian hackers exploit Zimbra zero-click flaw for email theft
Image: bleepingcomputer.com

Russian hackers are exploiting a zero-click flaw in Zimbra email servers to steal user data. The flaw, patched in November 2025, allows attackers to steal emails, passwords, and 2FA tokens without requiring user interaction. The attackers are using phishing attacks and adversary-in-the-middle (AiTM) kits to gain access to targets' email accounts.

Why it matters

This story matters because it highlights the ongoing threat of Russian state-sponsored hacking groups targeting organizations using Zimbra email servers. The exploit of the zero-click flaw demonstrates the importance of keeping software up-to-date and implementing robust security measures to prevent such attacks.

Imagine you receive an email that looks like it's from your email provider, but it's actually from a hacker. The hacker can steal your email, password, and special security codes without you even clicking on anything. This is called a zero-click flaw, and it's a big problem because it lets hackers get into your email account without you even knowing it.

Analysis

A Zero-Click Flaw in Zimbra Email Servers

The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, has been exploiting a zero-click flaw in Zimbra email servers to steal user data. The flaw, patched in November 2025, allows attackers to steal emails, passwords, and 2FA tokens without requiring user interaction. This exploit is particularly concerning because it demonstrates the ability of attackers to bypass traditional security measures and gain access to sensitive information.

The Exploit of the Zero-Click Flaw

The attackers are using phishing attacks and adversary-in-the-middle (AiTM) kits to gain access to targets' email accounts. The phishing attacks are designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies. The AiTM kits are used to create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows.

The Importance of Keeping Software Up-to-Date

The exploit of the zero-click flaw highlights the importance of keeping software up-to-date. Organizations using Zimbra email servers must ensure that they have installed all available security updates to prevent such attacks. Additionally, implementing robust security measures, such as phishing-resistant multi-factor authentication, can help prevent attackers from gaining access to sensitive information.

Key points

  • Russian hackers are exploiting a zero-click flaw in Zimbra email servers to steal user data.
  • The flaw, patched in November 2025, allows attackers to steal emails, passwords, and 2FA tokens without requiring user interaction.
  • The attackers are using phishing attacks and adversary-in-the-middle (AiTM) kits to gain access to targets' email accounts.
  • Organizations using Zimbra email servers must ensure that they have installed all available security updates to prevent such attacks.
  • Implementing robust security measures, such as phishing-resistant multi-factor authentication, can help prevent attackers from gaining access to sensitive information.
The Upside

If organizations using Zimbra email servers update to the latest version of the software and implement robust security measures, they can prevent such attacks from occurring. Additionally, the release of IOCs by CISA can help organizations identify and mitigate the threat.

The Downside

The exploit of the zero-click flaw demonstrates the ongoing threat of Russian state-sponsored hacking groups targeting organizations using Zimbra email servers. The attackers may continue to exploit this flaw until it is fully patched, and organizations must remain vigilant to prevent such attacks.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

TagssecurityhackingzimbraemailphishingaiTM

Author

Lawrence Abrams

Intelligence analysis by

Llama

Published

Jul 23, 2026

Source

bleepingcomputer.com

Share

Topics

securityhackingzimbraemailphishingaiTM

Related

More from this desk

Jul 23·bleepingcomputer.com

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan uses an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.

Jul 23·bleepingcomputer.com

Australian energy provider Origin says data breach exposes client data

Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). The company has 4.8 million customers and is currently investigating how many of them have been impacted to i…

Jul 23·thehackernews.com

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal mail and 2FA codes. The group targeted Western government and commercial organizations through Zimbra since at least July 2025.

Jul 23·wired.com

For Taylor Swift, Madison Square Garden’s Controversial Cameras Briefly Went Dark

Madison Square Garden owner James Dolan has insisted that the face-recognition system and array of surveillance cameras deployed at his venues is “very, very useful for security.” However, on the night of July 2, security in and around the Garden was particularly intense,…