CyberzSOC

Publication detail
← Back to advisories & guidance

Joint advisory on Russian cyber actors exploiting Zimbra Collaboration Suite ↗ source

July 24, 2026 ASD/ACSC Advisory

Summary

Today we released a joint advisory with international partners about cyber activity linked to the Russian state-sponsored group known as LAUNDRY BEAR. The advisory explains how the group used a previously unknown flaw in Zimbra Collaboration Suite (ZCS) to access organisations' email systems. Unlike most phishing attacks, this technique does not require a user to click a link or open a file. The attack can begin when a user simply views a malicious email in a vulnerable version of the webmail service. The group uses this technique to steal emails, contact lists and other sensitive information. They may also try to stay inside a compromised network so they can carry out more attacks.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.