
Russian Cyber Espionage Group Laundry Bear Exploited Zero-Day in Zimbra for Months
CybersecurityGeopoliticsGovernmentResearchThreatsAPTAustraliaCanadacyber_espionageCybersecurity_and_Infrastructure_Security_AgencyCzech_RepublicDenmarkespionageEstoniaFederal_Bureau_of_InvestigationFinlandFranceItalyLaundry_BearMoldovaNew_ZealandpayloadphishingPolandRussiaSpainSwedenThe_NetherlandsUkraineUnited_Kingdomzero_dayzero_day_exploitZimbra
The Russian cyber espionage group known as Laundry Bear exploited a zero-day vulnerability in Zimbra for five months before it was patched in November 2025. The group continues to actively target unpatched environments to steal sensitive data from Western countries. The campaign has impacted government and organizational targets across multiple nations, including Australia, Canada, Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, New Zealand, Poland, Spain, Sweden, the Netherlands, Ukraine, and the United Kingdom. No specific CVE ID was mentioned in the report. The attack vector involves phishing and malicious payloads to compromise systems.