Russian hackers use Zimbra vulnerability to steal sensitive emails

Hackers affiliated with the Laundry Bear group, a state-backed Russian hacking collective, have been exploiting an unpatched vulnerability in the Zimbra Collaboration Suite to access sensitive emails from government and commercial networks.

Laundry Bear, also known as Void Blizzard, CL-STA-1114, and TA488, has been targeting networks for at least a year with a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform.

The attackers are using a zero-day exploit in ZCS to gain unauthorized access to email accounts and sensitive data, including personal identifiable information (PII) and confidential business information.

Experts warn that the vulnerability remains unpatched and has been exploited by Laundry Bear to gain unauthorized access to sensitive emails from government and commercial networks worldwide.

Source: Help Net Security