Summary
The NSA, CISA, and allied intelligence agencies have issued a joint advisory warning that Russian state-sponsored threat actor TA488 — tracked as Void Blizzard and “Laundry Bear” — has been actively exploiting a previously unknown vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) to steal email correspondence from organizations in critical sectors. The campaign has been ongoing since 2025, with the advisory published July 23, 2026 following confirmation of continued active exploitation.
What makes this campaign particularly dangerous is the zero-click delivery mechanism. Targets do not need to click a link or open an attachment — simply receiving a specially crafted email message in a vulnerable Zimbra deployment is sufficient to trigger the exploit and allow the attackers to exfiltrate mailbox contents, including two-factor authentication codes. Targeted organizations span government, defense, nuclear research, and critical infrastructure sectors across NATO allies.
The advisory from the NSA urges all Zimbra Collaboration Suite users to apply available patches immediately, audit mail server logs for indicators of compromise, and review access patterns for anomalous inbox synchronization activity consistent with silent exfiltration.
Source
NSA Press Release — NSA and Partners Alert Zimbra Collaboration Suite Users
Proofpoint Threat Insight — TA488 Targets Zimbra Mail Servers
Commentary
Zero-click email exploits targeting mail server infrastructure are in a different threat category from most phishing campaigns. There’s no user behavior to train away, no attachment to sandbox, and no link to block. If you’re running an on-premises Zimbra deployment, you have a patching problem — not a user awareness problem. The fact that this has been running since 2025 with confirmed continued exploitation means defenders who haven’t patched yet have almost certainly already been compromised.
The targeting profile — nuclear scientists, defense contractors, government officials — tells you this is intelligence collection, not financial crime. Laundry Bear wants persistent access to high-value communications, and Zimbra’s widespread use across European government and NGO environments makes it an ideal vector. The advisory is overdue, but better late than never: patch, hunt, and assume breach.
