HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Zero‑Click Phishing Exploits Zimbra CVE‑2025‑66376, Exfiltrating Email Data Across Government and Finance Sectors

Unit 42 reports a Russian‑linked espionage campaign that uses a zero‑click phishing email to exploit CVE‑2025‑66376 in Zimbra Collaboration Suite, stealing credentials and up to 90 days of email history from government, defense, transportation, and financial organizations. The technique highlights the need for robust SOC 2 access‑control evidence and security‑awareness training.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 unit42.paloaltonetworks.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
unit42.paloaltonetworks.com

Zero‑Click Phishing Exploits Zimbra CVE‑2025‑66376, Exfiltrating Email Data Across Government and Finance Sectors

What Happened – Unit 42 tracked a nation‑state espionage campaign (CL‑STA‑1114) that leverages a zero‑click phishing email to exploit CVE‑2025‑66376 in the Zimbra Collaboration Suite (ZCS). The malicious JavaScript payload is injected automatically, stealing credentials, 2FA scratch codes, CSRF tokens, and up to 90 days of email/search history from targeted Zimbra servers.

Why It Matters for Compliance & Audit Readiness

  • The attack bypasses user interaction, exposing gaps in SOC 2 Access Control testing and the need for continuous monitoring of credential‑related controls.
  • Successful exfiltration of email archives can trigger privacy‑related audit findings (e.g., GDPR/CCPA) if personal data is not adequately protected.
  • Demonstrates the importance of Security Awareness Training that includes zero‑click phishing scenarios and verification of patch management processes.

Who Is Affected – Government agencies, defense ministries, transportation operators, and financial institutions that run unpatched Zimbra webmail installations in NATO, Ukraine, CIS, and African regions.

Recommended Actions

  • Apply the Zimbra security patch for CVE‑2025‑66376 immediately.
  • Deploy advanced email security (sandboxing, URL/attachment inspection) and enforce MFA for all webmail accounts.
  • Incorporate zero‑click phishing simulations into your Security Awareness program and document evidence for SOC 2 audit controls.

Technical Notes – The exploit uses a Base64‑obfuscated SVG element that decodes to JavaScript, which runs in the victim’s browser without any click. Data exfiltrated includes CSRF tokens, credentials, 2FA scratch codes, system details, and recent email/search history. Source: Palo Alto Unit 42

📰 Original Source
https://unit42.paloaltonetworks.com/russian-webmail-espionage/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →