HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Russian Hackers Exploit Unpatched Zimbra XSS (CVE‑2025‑66376) to Steal Emails Across Government and Commercial Sectors

Laundry Bear leveraged CVE‑2025‑66376 in unpatched Zimbra Collaboration Suite servers to steal email content, credentials, and MFA tokens from a broad set of government and commercial victims. The breach underscores the importance of timely patch management and SOC 2‑aligned access‑control evidence.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
7 sector(s)
Actions
4 recommended
📰
Source
helpnetsecurity.com

Russian Hackers Exploit Unpatched Zimbra XSS (CVE‑2025‑66376) to Steal Emails Across Government and Commercial Sectors

What Happened — The state‑backed group Laundry Bear has been leveraging CVE‑2025‑66376, a cross‑site scripting flaw in Zimbra Collaboration Suite, to harvest email content, credentials, and MFA tokens from vulnerable servers. The vulnerability was patched in November 2025, but attackers continue to target unpatched installations, exfiltrating up to 90 days of email data.

Why It Matters for Compliance & Audit Readiness

  • Unpatched software defeats the “patch‑management” control required by SOC 2 CC6.1, leaving organizations without defensible evidence of due diligence.
  • The view‑based XSS attack bypasses traditional phishing awareness training, highlighting the need for robust access‑control policies, MFA enforcement, and continuous monitoring of privileged email accounts.
  • Documenting remediation steps (patch rollout, configuration checks, log‑review) provides the audit‑ready artifacts that SOC 2 auditors expect for the Security and Confidentiality principles.

Who Is Affected — Federal, state, and local government agencies; defense industrial base; education institutions; energy utilities; law‑enforcement; media outlets; NGOs; and technology firms that run Zimbra on‑prem or in private clouds.

Recommended Actions

  • Verify Zimbra version across all mail servers; apply the November 2025 patch (or later) immediately.
  • Enable strict Content‑Security‑Policy (CSP) headers to mitigate XSS execution.
  • Enforce MFA for all email accounts and rotate tokens regularly.
  • Deploy email‑gateway scanning for malicious HTML payloads.
  • Update security‑awareness curricula to cover view‑based exploits and the importance of timely patching.
  • Capture patch‑deployment logs, configuration baselines, and monitoring alerts as SOC 2 evidence.

Source: Help Net Security

Technical Notes — CVE‑2025‑66376 is an XSS flaw that executes JavaScript when a crafted HTML email is opened in the Zimbra web client. Exploited code steals session cookies, passwords, 2FA tokens, and the Global Address List, then forwards data to Docker‑based exfiltration servers (Flowerbed) using encrypted traffic and VPN obfuscation. Source: same as above

📰 Original Source
https://www.helpnetsecurity.com/2026/07/24/laundry-bear-zimbra-vulnerability-cve-2025-66376/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →