What happened
A 31-page multinational advisory published on 23 July describes Laundry Bear, also tracked as Void Blizzard and TA488, exploiting CVE-2025-66376 against Zimbra Collaboration Suite. The flaw was used before its November 2025 patch and allows embedded JavaScript to execute when a targeted user views or previews a malicious email in the vulnerable Classic webmail client. No link click or attachment execution is required.
The Ulej or ZimReaper payload can gather recent email, contacts, passwords, 2FA scratch codes and environment data. It can create an application-specific password named ZimbraWeb for persistent IMAP, POP3 or SMTP access and use DNS and HTTPS channels for exfiltration. Proofpoint reports direct observations against Ukrainian, United States government, science and defence targets; its own telemetry had not observed activity after February 2026, while the government advisory says exploitation continues to succeed against unpatched systems.
Why this matters now
The campaign defeats the usual leadership assumption that phishing risk can be managed primarily through user behaviour. Viewing a message is enough, and compromised accounts are used to send subsequent messages, increasing trust and weakening gateway and awareness controls.
Patch deployment prevents the known client-side exploit but does not revoke application passwords, recover stolen authentication material or identify exported mail. The campaign therefore requires coordinated email, identity and data-exposure investigation rather than a software-only response.
The decision for security leaders
Make the first decision binary: either prove that all Zimbra systems were on a non-vulnerable release throughout the relevant period or begin a retrospective hunt. Where patching cannot be immediate, remove the vulnerable webmail experience from use.
Treat any ZimbraWeb application passcode, matching exploit email or high-risk SOAP sequence as a potential identity compromise. Revoke persistence, rotate credentials and determine whether the account sent messages to additional targets.
Assess the content and strategic sensitivity of affected mailboxes. Espionage impact can include negotiating positions, legal strategy, research, defence information and partner relationships even when no wider network intrusion is identified.
Evidence of closure
- A version inventory showing that no reachable Zimbra instance remains on a vulnerable build.
- Log-query results and analyst conclusions covering the commands, infrastructure and local-storage artefacts specified in the joint advisory.
- Identity-system evidence that malicious application passcodes and authentication material were revoked and affected credentials replaced.
- A mailbox-level exposure assessment identifying the users, dates and data potentially accessed.
The Security.io assessment
The decisive change is the breadth and authority of the disclosure. Multiple national agencies have provided technical detail, remediation steps and an attribution assessment, while Proofpoint supplies direct campaign telemetry and detection content. Confidence is high that the described exploitation and mailbox-theft technique is real; individual organisations must still establish whether they were targeted or compromised.
Security leaders should resist calling this only a legacy vulnerability. The current decision concerns persistence and information loss from exploitation that may have occurred before patching. Password resets alone are insufficient because application passcodes, 2FA material and browser or mailbox artefacts can support continued access or reveal the scope of theft.
The discrepancy between Proofpoint’s last directly observed activity and the government statement that exploitation continues should be interpreted as a difference in visibility, not proof that the campaign ended. Organisations should use the government advisory’s broader risk position until their own version history, logs, DNS data and mailbox evidence support a narrower conclusion.
Questions for the morning meeting
- Which sensitive business, diplomatic, defence or legal conversations were accessible in potentially affected mailboxes?
- Can the organisation revoke all forms of mailbox persistence rather than resetting passwords alone?
- Are Zimbra logs and DNS telemetry retained for the period beginning in July 2025?
- Which partners need warning if compromised accounts were used to send follow-on messages?