OFICIAL CISA News

CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity

What happened
Based on CISA News · Jul 23, 2026

U.S. agencies warn of Russian state-backed hackers exploiting a zero-click flaw in Zimbra Collaboration Suite to steal email data from Western organizations, including government and defense entities.

CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity
CISA News — CISA
Key points
·
WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S.
·
The advisory shares mitigations, indicators of compromise, and remediation to harden networks that use ZCS webmail against this ongoing threat activity.
·
This campaign uses a custom-developed aggregation and data exfiltration capability called Ulej to exploit a common vulnerabilities and exposures (CVE) in ZCS, CVE-2025-66376, with the potential for adaption to exploit other vulnerabilities as well.
·
This advisory provides several mitigations to protect against this activity and specific remediation actions for organizations that detect indicators of compromise in their environment.
Key numbers
·
The advisory highlights the use of a custom tool called Ulej to exploit CVE-2025-66376 and potentially others, enabling data exfiltration without user interaction.

The Cybersecurity and Infrastructure Security Agency (CISA), NSA, FBI, and partners issued a joint advisory detailing a phishing campaign by the Russian APT group LAUNDRY BEAR targeting Zimbra Collaboration Suite (ZCS) users. The campaign uses a zero-click exploit requiring only that a user views a malicious email in a vulnerable ZCS version, bypassing traditional phishing tactics. The advisory highlights the use of a custom tool called Ulej to exploit CVE-2025-66376 and potentially others, enabling data exfiltration without user interaction.

Since July 2025, over 10 organizations using ZCS have been compromised, with attackers stealing sensitive data such as email addresses, passwords, and two-factor authentication tokens. Targeted sectors include the Defense Industrial Base, federal and local governments, law enforcement, technology, education, media, and non-governmental organizations. The advisory provides mitigations and remediation steps to harden ZCS deployments against this activity.

CISA Acting Executive Assistant Director for Cybersecurity Chris Butera emphasized the growing sophistication of nation-state cyber threats, urging organizations to update ZCS software and monitor email services for malicious activity. The FBI’s Assistant Director Brett Leatherman noted that Russian state-sponsored actors have long targeted critical infrastructure, and this advisory aims to help defenders detect and counter such operations.

The advisory follows recent disclosures of LAUNDRY BEAR’s activities, which have focused on extracting configuration data from poorly secured routers. Organizations are advised to implement the recommended mitigations immediately to reduce exposure to this and similar threats. Further details on nation-state cyber threats are available on CISA’s website.

Original source → Deals on Clipraptor.com →