The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about ongoing attacks targeting Zimbra Collaboration email servers. The Russian state-sponsored hacking group known as Laundry Bear, or Void Blizzard, is combining phishing campaigns with the exploitation of a vulnerability that has already been patched by Zimbra. The attacks aim to steal email data from affected organizations.
What happened
CISA’s advisory states that Laundry Bear is actively targeting organizations using Zimbra Collaboration servers. The group is leveraging a known security flaw in the software, which Zimbra addressed in a prior update. However, unpatched servers remain vulnerable to exploitation. The attacks do not rely solely on the vulnerability; phishing emails are also being used to gain initial access to targeted systems. The source did not specify the number of victims or the sectors most affected.
The advisory does not detail the exact timeline of the attacks, but it confirms that the vulnerability in question has been publicly known and patched. Organizations that have not applied the update are at risk of email theft and further compromise.
What we don’t know yet
The advisory does not provide information on the scale of the attacks, such as the number of compromised organizations or the specific data accessed. It also does not clarify whether the phishing component of the attack involves novel techniques or known methods. Additionally, the timing of the initial exploitation remains unclear, as the source does not specify when the attacks began or whether they are ongoing.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 23 Jul 2026. First draft failed editor review; a revised version was approved (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Follow-up story New development on Zimbra vulnerability exploitation by Russian hackers.; matched_article_id=307
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=351 slug=russian-hackers-exploit-patched-zimbra-flaw-in-email-theft quick_read=1
-
Editor review — Rejected
- Score: 85/100
- Factual grounding: Source does not mention 'zero-click flaw'—it describes the attack as combining phishing with exploitation of a patched vulnerability. The term 'zero-click' is not supported by the source text.
- Quote integrity: No blockquotes are used in the draft, so this check is not applicable. However, the draft does not misrepresent any quotes.
- No copied phrasing: The phrase 'Laundry Bear, or Void Blizzard' closely mirrors the source wording. While not a direct copy, it is a minor echo of the source phrasing.
- Style compliance: The draft adheres to the structure and tone guidelines, but the headline slightly exceeds the 90-character limit (92 characters).
- Sanity: The headline, standfirst, and body are aligned, and the category is appropriate. No half-finished sentences or JSON artifacts are present.
- Audience relevance and notability: The story is highly relevant to hosting, email, and security professionals, with clear actionable implications for patching and monitoring.
- Writing the article — Rewritten editor-driven rewrite
-
Editor review — Approved
- Score: 85/100
- Factual grounding: Source does not mention 'zero-click flaw' in the title or body, yet the draft headline and standfirst include 'patched flaw' without clarifying if it is zero-click. The source describes the vulnerability as 'now-patched' but does not specify if it is zero-click. Avoid implying specifics not in sources.
- Quote integrity: No blockquotes are used in the draft, but the rule is noted for compliance. No verbatim quotes are present in the source to include.
- No copied phrasing: Draft closely echoes source phrasing in places (e.g., 'combining phishing campaigns with the exploitation of a vulnerability that has already been patched'). Restructure to avoid similarity.
- Style compliance: Standfirst is slightly vague ('email theft by state-backed group using phishing and exploits'). Specify the exploit is a patched Zimbra flaw to align with headline precision.
- Audience relevance and notability: Story is relevant to email/DNS professionals due to Zimbra's use in hosting environments, but the lack of victim/impact details limits actionable takeaways. This is defensible given the advisory nature of the source.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Reused library image reused image #1
- Linking related stories — Linked 2 relations from 296 candidates
- Publishing — Published russian-hackers-exploit-patched-zimbra-flaw-in-email-theft
- Mastodon — Posted https://mstdn.social/@hostingpaper/116970565240400666



Discussion · coming soon
Be the first to join the thread when community discussion launches.