HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High ThreatIntel

Russian APT ‘LAUNDRY BEAR’ Phishing Campaign Exploits Zero‑Day in Zimbra Collaboration Suite (CVE‑2025‑66376)

Russian state‑supported actors have been running a phishing campaign against Zimbra Collaboration Suite users, leveraging a zero‑day (CVE‑2025‑66376) that was patched in November 2025. The activity highlights the need for robust security‑awareness training and auditable patch‑management to meet SOC 2 requirements.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 cisa.gov
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
cisa.gov

Phishing Campaign Leveraging Zero‑Day in Zimbra Collaboration Suite (CVE‑2025‑66376) Targets Western Organizations

What It Is — Russian state‑supported APT “LAUNDRY BEAR” has been running a high‑volume phishing campaign against users of the Zimbra Collaboration Suite (ZCS) since July 2025. The actors combine classic credential‑spraying and phishing with a novel zero‑day exploit (CVE‑2025‑66376) that was patched in November 2025.

Exploitability — The zero‑day was actively exploited in the wild before the November patch; public proof‑of‑concept details have been shared in CISA advisories. CVSS ≈ 9.8 (critical) for remote code execution via crafted email content.

Affected Products — Zimbra Collaboration Suite (on‑premise and cloud‑hosted deployments).

Why It Matters for Compliance & Audit Readiness

  • Security Awareness Training – Phishing remains the most common initial‑access vector; auditors now expect documented, regularly‑tested training programs as evidence of SOC 2 CC6.1 controls.
  • Access‑Control Monitoring – Successful credential‑spraying highlights the need for continuous MFA enforcement and privileged‑access review, which map to SOC 2 CC6.2.
  • Patch Management Evidence – The rapid exploitation of CVE‑2025‑66376 underscores the importance of maintaining auditable patch‑deployment logs to satisfy SOC 2 CC7.1.

Recommended Actions

  • Verify that all Zimbra instances are patched to the November 2025 release or later; capture patch‑installation logs for audit.
  • Enforce MFA for all remote Zimbra access and review privileged accounts against SOC 2 CC6.2 requirements.
  • Launch a targeted phishing simulation program and record employee completion rates as evidence of security‑awareness controls.
  • Update incident‑response playbooks to include zero‑day email‑exploit detection and containment steps.

Source: CISA Advisory AA26‑204A

📰 Original Source
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →