Laundry Bear, also known as Void Blizzard, CL-STA-1114, and TA488, has been targeting networks for at least a year with a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform.
The attackers are using a zero-day exploit in ZCS to gain unauthorized access to email accounts and sensitive data, including personal identifiable information (PII) and confidential business information.
Experts warn that the vulnerability remains unpatched and has been exploited by Laundry Bear to gain unauthorized access to sensitive emails from government and commercial networks worldwide.