惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
Martin Fowler
Martin Fowler
MongoDB | Blog
MongoDB | Blog
Engineering at Meta
Engineering at Meta
Stack Overflow Blog
Stack Overflow Blog
Google DeepMind News
Google DeepMind News
Microsoft Security Blog
Microsoft Security Blog
aimingoo的专栏
aimingoo的专栏
I
InfoQ
B
Blog
WordPress大学
WordPress大学
Jina AI
Jina AI
小众软件
小众软件
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
酷 壳 – CoolShell
酷 壳 – CoolShell
阮一峰的网络日志
阮一峰的网络日志
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
G
Google Developers Blog
C
Check Point Blog
月光博客
月光博客
L
LangChain Blog
GbyAI
GbyAI

Proofpoint News Feed

Proofpoint Expands AI-Powered Investigations to Microsoft 365 and Deepens Insider Risk Visibility into AI Activity | Proofpoint US Four groups caught using the same Chrome and Windows exploit kit CISOs are feeling the security burden of accelerated AI use Chinese espionage groups swarm to exploit triple-link chain of zero-days Proofpoint 2026 Voice of the CISO Report Finds Cyber Resilience Improving, While AI Expands the CISO Mandate | Proofpoint US Proofpoint SOC Analyst Agent Uses OpenAI Cyber Models Proofpoint Strengthens Executive Leadership Team with Appointment of Chief Legal Officer and Chief People Officer | Proofpoint US Proofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster | Proofpoint US Cybercriminals Turn to Indirect Prompt Injection Attacks Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats | Proofpoint US Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities | Proofpoint US Max-severity Exchange server flaw under active exploitation by Kremlin hackers New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors | CNN Politics International alert spotlights Russia-linked attacks on Zimbra webmail US and allies say Russian hackers stole emails without social engineering If you pay a hacker's ransom, chances are that they'll come back for more | TechCrunch Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective | Proofpoint US The Hacker News Hackers find a new trick to collect Microsoft Entra user data without raising red flags Suspected Chinese snoops caught breaking into universities New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams Defending the Authentication Flow: Device Code Phishing with Selena Larson Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense | Proofpoint US OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Suspected North Korean actors use fake ‘coding assignments’ to steal crypto China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era | Proofpoint US Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Proofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to Claude | Proofpoint US Proofpoint Launches Dedicated MSP Business Unit and Introduces 365 Total Protection for North America | Proofpoint US
Fox News
Kurt Knutsson, CyberGuy Report · 2026-08-07 · via Proofpoint News Feed

NEWYou can now listen to Fox News articles!

Opening an unexpected email can feel relatively harmless when you avoid its links and attachments. However, a Russian hacking campaign has turned that familiar safety advice on its head.

CISA says the Russian state-sponsored group Laundry Bear can compromise certain email accounts when someone simply opens or previews a malicious message. The attack targets organizations running unpatched versions of the Zimbra Collaboration Suite.

Once the email appears, hidden code can collect passwords, authentication data and as much as 90 days of messages. You may never see a warning or realize that anything happened.

The Cybersecurity and Infrastructure Security Agency issued the warning with the National Security Agency, FBI and cyber authorities from several allied countries. The agencies say the group has successfully targeted more than 10 Western organizations since July 2025.

INVESTIGATORS BELIEVE IRANIAN HACKERS ARE LIKELY BEHIND CYBERATTACK ON MINNESOTA WATER SYSTEMS: REPORT

A computer screen with code

Russian state-sponsored hackers can steal passwords, two-factor authentication tokens and up to 90 days of email when users view malicious messages in unpatched Zimbra accounts. (Kurt "CyberGuy" Knutsson)

CyberGuy Live: Missed "Sick of Spam?" Get the replay and checklist

Our free CyberGuy Live class, "Sick of Spam?" has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt "CyberGuy" Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.

Get the free replay and checklist now at CyberGuyLive.com.

Russian hackers can steal emails without a normal click

Laundry Bear, which Microsoft tracks as Void Blizzard, exploits a security flaw known as CVE-2025-66376. The cross-site scripting vulnerability affects the Classic user interface in certain versions of the Zimbra Collaboration Suite.

Zimbra is an email and collaboration platform used by some governments, schools, businesses and other organizations as an alternative to services such as Microsoft Exchange or Google Workspace. Attackers can place malicious JavaScript inside a specially crafted HTML email. That code runs automatically when a vulnerable Zimbra webmail client displays the message.

The person reading the email does not need to open an attachment. The attack also avoids the usual request to enter a password on an obvious phishing page. However, the email still needs to appear on the screen. CISA describes the technique as a zero-click exploit. Proofpoint calls it a "half-click" attack because someone must open the email or allow it to appear in a preview pane. Either description leads to the same concern. A message can look harmless while code hidden inside it quietly attacks the email account.

The email security flaw was patched in 2025

Laundry Bear reportedly used the flaw as a zero-day before Zimbra released a patch in November 2025. A zero-day attack exploits a security weakness before the software maker provides a fix. CISA later added the vulnerability to its list of flaws that hackers actively exploit.

The available patch closes the known security hole. Yet Laundry Bear continues to target organizations that have not installed the update. That makes delayed patching especially dangerous. An organization may have strong passwords and trained employees, but an exposed email server can still give attackers another way inside.

The campaign has reached organizations connected to the defense industrial base and government. Attackers have also targeted education, energy, law enforcement, media, nonprofit groups and technology companies.

One email can expose 90 days of messages

According to CISA, the malicious code attempts to collect the target's last 90 days of email. That could include private conversations with coworkers, contract discussions or information about upcoming meetings. An inbox may also contain password reset notices, invoices and documents that reveal how an organization operates.

Laundry Bear also collects the person's email address and password. The attack can copy the organization's Global Address List, which acts as a directory of employees and contacts. The hackers may then gain enough information to impersonate a trusted coworker or identify more valuable accounts.

CISA says the exploit also targets two-factor authentication tokens. Those tokens help prove that someone has already completed an authentication step. A stolen token or session cookie can let an attacker enter an account without completing the normal login process again.

FAKE PASSWORD-MANAGER ALERTS COULD PUT YOUR VAULT AT RISK

Split image of an email and a man in a hoodie with computers in the background

Malicious code hidden inside an email can run when a vulnerable Zimbra webmail client displays the message, giving hackers access to sensitive account data. (Getty Images)

Hackers can create a hidden way back into an account

Stealing information provides immediate value, but Laundry Bear also tries to preserve its access. The attack creates a new Zimbra application passcode and sends it back to the hackers. Legacy email programs use these passcodes when they connect through services such as IMAP or ActiveSync and cannot support modern time-based authentication.

An unauthorized passcode can give the hackers another entrance to the mailbox. That access may continue even after someone changes the main account password. CISA has urged administrators to look for suspicious application passcodes, particularly passcodes labeled "ZimbraWeb."

Organizations should treat an unknown passcode as a sign that someone may have entered the account. Simply installing the patch after a compromise may leave the attacker's access in place.

How the stolen email data leaves the network

Laundry Bear sends the stolen information to servers controlled by the group. CISA says the attackers use a collection framework called Flowerbed. The system moves smaller pieces of data through Domain Name System requests. DNS normally helps computers find websites and online services.

Attackers can hide encoded information inside those requests. Because organizations generate large amounts of legitimate DNS traffic, the malicious activity may blend into the background. Laundry Bear sends larger collections through encrypted HTTPS connections. That can include compressed archives containing mailbox data. Security teams may need to inspect network logs, authentication records and mailbox activity to understand what left the organization.

Fake email login pages provide another route

Laundry Bear also uses adversary-in-the-middle phishing kits. These tools create login pages that closely resemble legitimate email portals. When someone enters a username and password, the phishing system captures those credentials. It can also intercept session cookies created during the login process. That means an attacker may gain access even when the account uses conventional multifactor authentication.

CISA's indicators of compromise include domains that impersonated Zimbra infrastructure. Examples include mailnalysis.com, zimbrastat.com, zimbra-metadata.com and zmailanalytics.com. The presence of one of these domains in network logs could point to phishing or unauthorized account activity. However, organizations should review CISA's complete list because attackers can change their infrastructure.

Proofpoint found that Laundry Bear sent messages from attacker-controlled Proton Mail accounts and email addresses the group had already compromised. In one example, the sender claimed to represent a Belgian media-verification organization. The email proposed cooperation between European institutions fighting disinformation. It included a legitimate-looking link to a European Union events calendar. However, the malicious code sat inside the email rather than the linked website.

Laundry Bear has targeted governments and Ukraine

Dutch intelligence agencies publicly identified Laundry Bear in May 2025. Their investigation linked the group to a 2024 breach of the Dutch National Police. That incident exposed personal information belonging to police personnel. Investigators said the attack helped them identify a previously unknown Russian cyberespionage group.

Since at least 2024, Laundry Bear has focused on organizations connected to Russian strategic interests. Its targets have included NATO member states and groups supporting Ukraine.

Microsoft has documented compromises involving defense organizations as well as entities in transportation and aviation.A separate campaign targeted members of Ukraine's military with charity-themed phishing emails. Those messages disguised malware as requests for donations.

These campaigns suggest the group cares more about long-term intelligence collection than a quick financial payout. Access to email can reveal relationships, future plans and internal decisions.

PAIDWORK BREACH EXPOSES 23M USER RECORDS

A person wearing a watch types on a laptop.

CISA warns that Laundry Bear can compromise vulnerable Zimbra accounts without requiring users to click a link or open an attachment. (shapecharge/Getty Images)

Ways to stay safe from the email attack

The strongest protection starts with the organization running the email server because employees cannot personally patch a vulnerable installation. However, you can still take steps to spot suspicious activity and protect your other accounts.

1) Install every available email security update

Administrators should update Zimbra Collaboration Suite to a currently supported version and install all available security fixes. Organizations should confirm that the patch reached every server. An overlooked system may remain exposed even when the primary mail server has received the update.

2) Look for evidence that attackers already got inside

Installing the patch blocks the known flaw, but it cannot undo a previous intrusion. Security teams should review CISA's published indicators of compromise. They should also search network records for connections to the listed domains and IP addresses. Authentication logs may reveal unusual locations, unexpected devices or activity outside normal working hours.

3) Remove unauthorized application passcodes

Review every Zimbra application passcode connected to an account. Pay close attention to unfamiliar entries and anything labeled "ZimbraWeb." Revoke any passcode that the account owner or IT department cannot verify. Because application passcodes can survive a regular password change, this review plays an important role in removing persistent access.

4) Check accounts for unauthorized mailbox activity

Administrators should examine mailbox access records and forwarding settings. They should also look for unfamiliar filters, deleted messages or sent emails that the account owner does not recognize. A compromised account may send convincing phishing messages to coworkers because the email comes from a trusted internal address.

5) Report suspicious activity to your IT department

Contact your IT or security team if you notice unfamiliar sent messages, unexpected password resets or login alerts you cannot explain. Do not rely only on changing your password. Laundry Bear can create an application passcode that may continue providing mailbox access after the main password changes. Your IT team should revoke unauthorized passcodes, end active sessions and check the account for suspicious activity.

6) Change exposed passwords after the account is secured

Wait until your IT department has patched the server and removed unauthorized access. Then change your email password and any other password you reused. Create a unique password for every account. A password manager can generate strong credentials and store them securely. Hackers may test stolen email credentials on banking, shopping or social media accounts. Reused passwords can turn one compromised inbox into several compromised accounts.

7) Use phishing-resistant authentication

CISA recommends phishing-resistant multifactor authentication where organizations can support it. Security keys and passkeys provide stronger protection than methods that rely on temporary codes. However, organizations still need to patch the underlying email software. Authentication controls cannot fully protect an account when malicious code runs inside a vulnerable webmail interface.

8) Use strong antivirus software on your devices

Strong antivirus software can help detect malicious downloads, fake login pages and follow-up malware connected to a broader phishing campaign. However, antivirus software may not stop this email exploit because the malicious code runs inside a vulnerable webmail session. Your organization still needs to update Zimbra and investigate the account for unauthorized access. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.

9) Treat unexpected login prompts with caution

An email login page can look convincing and still belong to an attacker. Instead of following a link inside an email, open your organization's known webmail address directly. Report unfamiliar authentication requests or repeated sign-in prompts to your security team. A sudden request to log in again could signal a phishing attempt or unauthorized account activity.

Kurt's key takeaways

For years, we have warned you to avoid suspicious links and unexpected attachments. That advice still helps, but Laundry Bear shows why your organization also needs to keep the software behind your inbox updated. In this campaign, viewing an email can trigger malicious code on an unpatched server. The attackers can then reach into the mailbox, collect months of messages and steal authentication data. The hidden application passcode adds another concern. Changing a password may provide a false sense of security when an attacker has already created a separate route back into the account. Organizations using Zimbra should patch immediately and then investigate for signs of earlier access. Employees should remain cautious around unexpected login pages, even when the page carries familiar company branding.

Would you trust your workplace inbox if opening one message could expose 90 days of email without you clicking a link? Let us know by writing to us at CyberGuy.com.

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com - trusted by millions who watch CyberGuy on TV daily.
  • Plus, you'll get instant access to my Ultimate Scam Survival Guide free when you join.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Copyright 2026 CyberGuy.com. All rights reserved.

Kurt "CyberGuy" Knutsson is an award-winning tech journalist who has a deep love of technology, gear and gadgets that make life better with his contributions for Fox News & FOX Business beginning mornings on "FOX & Friends." Got a tech question? Get Kurt’s free CyberGuy Newsletter, share your voice, a story idea or comment at CyberGuy.com.