Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, TechTalk

Russian Laundry Bear Exploits Zimbra Zero-Click Flaw to Steal NATO Emails and 2FA Codes — What Canadian Organizations Must Do Now

What Happened

CISA, NSA, FBI, and partner agencies from the UK, Australia, Canada, and other allied nations issued joint advisory AA26-204A on July 23, 2026, warning of active exploitation of CVE-2025-66376 — a cross-site scripting (XSS) flaw in the Zimbra Collaboration Suite (ZCS) webmail client. The threat actor behind the campaign is Laundry Bear, also tracked as Void Blizzard, CL-STA-1114, and TA488, a Russian state-backed espionage group assessed to be collecting intelligence for the Russian Federation.

The vulnerability arises from insufficient sanitization of CSS @import directives in email content. When a victim opens or previews a malicious message in Zimbra webmail, the embedded XSS payload fires automatically — no link click required. The exploit collects the victim’s last 90 days of email, email address and password, the organization’s Global Address List (GAL), two-factor authentication tokens, and newly created application passcodes. That data is then exfiltrated to attacker-controlled infrastructure. Synacor patched CVE-2025-66376 in November 2025, but Laundry Bear had been exploiting it as a zero-day since at least July 2025 — months before the patch existed.

Confirmed targets include government ministries, defence contractors, energy companies, technology firms, media organizations, law enforcement agencies, and non-governmental organizations across the US, Ukraine, and NATO member states.

Why This Matters for Canadian Organizations

Canada is a NATO member, a Five Eyes partner, and a named co-signer of advisory AA26-204A. The advisory’s breadth of targeting — government, defence, energy, and media — maps directly onto Canadian federal departments, Crown corporations, defence contractors, and the broader critical infrastructure sector. Any Canadian organization running on-premises Zimbra Collaboration Suite that has not applied the November 2025 patch is at risk of a silent, zero-click email compromise.

The theft of 2FA tokens is particularly significant. An attacker who obtains a valid session token and a current OTP code bypasses multi-factor authentication entirely, enabling persistent access that survives password resets. For organizations handling sensitive government communications or protected B information, this represents a serious breach of confidentiality obligations under PIPEDA and federal policy frameworks. The CCCS has co-signed this advisory, signalling direct relevance for Canadian public sector and critical infrastructure operators.

What to Do

Apply the Zimbra security update for CVE-2025-66376 immediately if your organization runs self-hosted Zimbra. Review CISA’s published indicators of compromise and search your Zimbra logs for suspicious SOAP requests, newly created application passcodes, unexpected IMAP enablement, and unusual HTTPS connections from the webmail system. Treat any unpatched Zimbra instance as already compromised and conduct a forensic review of outbound connections and email access logs from the past 12 months. If you use Zimbra for government or defence-adjacent communications, report suspected incidents to the CCCS at cyber.gc.ca. Organizations subject to OSFI Guideline B-13 should assess whether this vulnerability exposure triggers incident notification obligations.

Source: BleepingComputer | CISA Advisory AA26-204A

Enjoy this article? Don’t forget to share.