Phishing Campaign Leveraging Zero‑Day in Zimbra Collaboration Suite (CVE‑2025‑66376) Targets Western Organizations
What It Is — Russian state‑supported APT “LAUNDRY BEAR” has been running a high‑volume phishing campaign against users of the Zimbra Collaboration Suite (ZCS) since July 2025. The actors combine classic credential‑spraying and phishing with a novel zero‑day exploit (CVE‑2025‑66376) that was patched in November 2025.
Exploitability — The zero‑day was actively exploited in the wild before the November patch; public proof‑of‑concept details have been shared in CISA advisories. CVSS ≈ 9.8 (critical) for remote code execution via crafted email content.
Affected Products — Zimbra Collaboration Suite (on‑premise and cloud‑hosted deployments).
Why It Matters for Compliance & Audit Readiness
- Security Awareness Training – Phishing remains the most common initial‑access vector; auditors now expect documented, regularly‑tested training programs as evidence of SOC 2 CC6.1 controls.
- Access‑Control Monitoring – Successful credential‑spraying highlights the need for continuous MFA enforcement and privileged‑access review, which map to SOC 2 CC6.2.
- Patch Management Evidence – The rapid exploitation of CVE‑2025‑66376 underscores the importance of maintaining auditable patch‑deployment logs to satisfy SOC 2 CC7.1.
Recommended Actions
- Verify that all Zimbra instances are patched to the November 2025 release or later; capture patch‑installation logs for audit.
- Enforce MFA for all remote Zimbra access and review privileged accounts against SOC 2 CC6.2 requirements.
- Launch a targeted phishing simulation program and record employee completion rates as evidence of security‑awareness controls.
- Update incident‑response playbooks to include zero‑day email‑exploit detection and containment steps.
Source: CISA Advisory AA26‑204A