CRITICAL ⚡ MUST-KNOW
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
A state-sponsored group tracked as “Laundry Bear” is exploiting a Zimbra zero-day against targets in the US and Ukraine. The group sends “half-click” phishing emails that require a victim only to open or preview the message to trigger exploitation, rather than click a link or open an attachment.
Organizations running Zimbra should watch for anomalous mail-preview activity and apply vendor guidance as it becomes available. No patch details were available at time of writing.