HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Zero‑Click Phishing Campaign Exploits Zimbra Webmail (CVE‑2025‑66376) Targeting Government and Financial Entities

Russian‑aligned APT Laundry Bear leveraged CVE‑2025‑66376 in Zimbra Collaboration Suite to deliver a zero‑click JavaScript payload, exfiltrating emails and credentials from government, defense and financial organizations. The incident underscores the importance of SOC 2‑aligned access‑control policies and continuous audit evidence of patch management.

LiveThreat™ Intelligence · 📅 July 23, 2026· 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
therecord.media

Zero‑Click Phishing Campaign Exploits Zimbra Webmail (CVE‑2025‑66376) Targeting Government and Financial Entities

What Happened — Russian‑aligned APT group Laundry Bear leveraged a zero‑click exploit (CVE‑2025‑66376) in Zimbra Collaboration Suite’s webmail to deliver a malicious JavaScript payload that runs as soon as an email is opened. The campaign has hit U.S., U.K., European, Australian, New Zealand, Ukrainian and NATO‑linked organizations, exfiltrating recent emails, passwords, contact lists and two‑factor tokens.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how a patched vulnerability can be weaponised in a “zero‑click” scenario, bypassing traditional user‑training controls.
  • Highlights the need for SOC 2‑aligned access‑control policies, continuous monitoring of privileged account activity, and evidence that patch management is enforced and auditable.
  • Provides a real‑world example to validate that your organization can produce defensible audit evidence of credential‑access restrictions and incident‑response readiness.

Who Is Affected – Government agencies, defense contractors, transportation firms, financial services, and maritime organizations that run Zimbra Collaboration Suite.

Recommended Actions

  • Verify that all Zimbra deployments are running the November 2025 patch (or later) for CVE‑2025‑66376.
  • Enable multi‑factor authentication (MFA) on all webmail accounts and enforce strict session‑monitoring controls.
  • Incorporate the exploit into your SOC 2 access‑control testing regime and capture evidence of remediation for audit purposes.

Technical Notes – The attack uses a zero‑click, cross‑site‑script payload embedded in email bodies; no user interaction is required. Data exfiltrated includes the last 90 days of email, credentials, contact lists, and MFA tokens. Source: The Record

📰 Original Source
https://therecord.media/zimbra-webmail-zero-click-phishing-russia-laundry-bear

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →