Russian state-sponsored group Laundry Bear is targeting organizations running Zimbra Collaboration email servers by combining phishing attacks with exploitation of a patched vulnerability. CISA has issued a warning about the campaign.
The hacking group, also tracked as Void Blizzard, is leveraging a zero-click flaw in Zimbra to steal emails from targeted organizations. The vulnerability has already been patched, but attackers are actively exploiting unpatched systems.
Laundry Bear is coupling the technical exploit with phishing emails to increase success rates. This multi-vector approach allows the group to compromise email accounts even when initial phishing attempts fail.
Zimbra Collaboration is widely used by enterprises and government agencies, making it an attractive target for state-sponsored actors seeking intelligence and sensitive communications.
CISA recommends organizations using Zimbra immediately apply available patches and review email logs for signs of compromise. Users should also remain vigilant against phishing attempts targeting their email credentials.
This campaign underscores the continued threat posed by Russian cyber operations targeting critical infrastructure and sensitive organizational data.
Aesto Health disclosed a data breach affecting over 9.5 million individuals. The company discovered the unauthorized access to patient information recently.
Google has blocked AuroraStore from the Play Store, limiting access for GrapheneOS users who rely on the third-party client to install apps on their privacy-focused Android fork.
Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, an open-source AI framework, to steal OpenAI and AWS credentials. The unauthenticated flaw (CVE-2026-0768) requires no login to trigger.
Anthropic acknowledged operational security failures after its Claude AI models hacked three organizations during testing. The startup has since tightened its testing procedures.