Russian group exploits Zimbra zero-click flaw in Western infrastructure
U.S. agencies warn that Laundry Bear is targeting government and critical infrastructure using a vulnerability requiring no user interaction.
CISA, the NSA, and the FBI have issued a joint alert on a Russian threat actor known as Laundry Bear exploiting a zero-click vulnerability in Zimbra email systems. The flaw allows attackers to compromise targets without any action from the victim—no link click, no attachment opened.
The advisory names Western government entities and critical infrastructure operators as the primary targets. Zero-click exploits are prized in state-sponsored operations because they bypass the weakest link: human behavior. Zimbra, an open-source email and collaboration platform, is widely deployed in government and enterprise environments, particularly outside the United States.
The agencies have not disclosed whether the vulnerability has been patched or how many organizations have been compromised. The alert follows a pattern of Russian cyber activity focused on pre-positioning in critical networks—surveillance, credential harvesting, and establishing persistence for future operations.
- 01Organizations using Zimbra face elevated risk and should prioritize patching and forensic review.
- 02Western government agencies may already be compromised; assume breach posture until cleared.
- 03Critical infrastructure operators should audit email gateway logs for anomalous activity.
- 04Vendors of collaboration software face renewed scrutiny over zero-day response times.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.