Skip to content
feed: live
>_ 0dayNews
zimbra
● Breaking

Void Blizzard Exploits Zimbra Flaw for Email Theft

CISA warns Russian state-sponsored Void Blizzard (Laundry Bear) is combining phishing with a patched Zimbra zero-click flaw to steal email from targeted organizations.

Void Blizzard Exploits Zimbra Flaw for Email Theft
Photo: Raimond Spekking / Wikimedia Commons · CC BY-SA 4.0
airgap airgap · Published · 1 min read

Confirmed active campaign. CISA is warning that Void Blizzard — the Russian state-sponsored group also tracked as Laundry Bear — is exploiting a patched zero-click vulnerability in Zimbra Collaboration to steal email from targeted organizations. BleepingComputer reported July 23, 2026.

Confidence

  • Confirmed: Void Blizzard (Laundry Bear) is the attributed actor — Russian state-sponsored, per CISA.
  • Confirmed: Attack chain combines phishing with exploitation of a now-patched Zimbra flaw.
  • Confirmed: Objective is email theft from targeted organizations.
  • Confirmed: The Zimbra flaw is zero-click — no user interaction required beyond receiving the email.
  • Unconfirmed: Specific CVE identifier for the Zimbra vulnerability — check CISA’s advisory directly; do not treat any unverified identifier as confirmed.
  • Unconfirmed: Full target scope. Void Blizzard has historically focused on NATO-adjacent government and defense organizations; current breadth is uncharacterized.

What’s happening

Void Blizzard runs two tracks simultaneously: phishing to establish initial access and a zero-click Zimbra flaw for direct email collection without needing credentials. The zero-click component is the more severe track — it doesn’t require a target to click anything. A vulnerable, internet-exposed Zimbra server receiving external email is sufficient exposure.

Zimbra Collaboration is common in organizations that self-host email, particularly in government and defense sectors — a consistent target profile for Russian intelligence-linked actors collecting diplomatic and strategic communications.

The patch is available. Exploitation is active. The window between those two facts is the risk.

What to do

Patch Zimbra Collaboration to the current release. Verify it applied — don’t assume the update ran successfully. If your Zimbra environment accepts email from the internet and is running a vulnerable build, patch now, not at the next maintenance window.

Review CISA’s advisory for IOCs and the specific vulnerability identifier. BleepingComputer’s report carries additional context on the campaign attribution and attack chain details.

Prior Zimbra exploitation by state-sponsored actors is a well-documented pattern — this is consistent with known Void Blizzard tradecraft, not an anomaly.

Found this useful? Share it.