{"id":1080,"date":"2026-07-24T08:59:02","date_gmt":"2026-07-24T06:59:02","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=1080"},"modified":"2026-07-27T09:00:12","modified_gmt":"2026-07-27T07:00:12","slug":"russian-state-backed-threat-actor-exploits-zimbra-zero-day-to-steal-emails-authentication-data","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/07\/24\/russian-state-backed-threat-actor-exploits-zimbra-zero-day-to-steal-emails-authentication-data\/","title":{"rendered":"Russian State-Backed Threat Actor Exploits Zimbra Zero-Day To Steal Emails &amp; Authentication Data"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A Russian state-supported hacking group has been exploiting a previously unknown vulnerability in Zimbra Collaboration Suite to silently steal emails, passwords, two-factor authentication codes and corporate address books from government and commercial organizations across Western countries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The campaign, attributed to a threat group primarily known as Laundry Bear, has been active since at least July 2025 and represents a significant escalation in the group\u2019s technical capabilities. Unlike conventional phishing attacks, the operation does not require victims to click a malicious link, download an attachment or enter credentials into a fraudulent website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/pulse\/warning-russian-state-backed-laundry-bear-exploits-4c3we\/\">(8) WARNING: Russian State-Backed Threat Actor Exploits Zimbra Zero-Day To Steal Emails &amp; Authentication Data | LinkedIn<\/a><\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/07\/24\/russian-state-backed-threat-actor-exploits-zimbra-zero-day-to-steal-emails-authentication-data\/\" target=\"_self\">Lees verder<span class=\"screen-reader-text\">: Russian State-Backed Threat Actor Exploits Zimbra Zero-Day To Steal Emails &amp; Authentication Data<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>A Russian state-supported hacking group has been exploiting a previously unknown vulnerability in Zimbra Collaboration Suite to silently steal emails, passwords, two-factor authentication codes and corporate address books from government and commercial organizations across Western countries. The campaign, attributed to a threat group primarily known as Laundry Bear, has been&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24,3],"tags":[72,9],"class_list":["post-1080","post","type-post","status-publish","format-standard","hentry","category-datalek","category-malware","tag-72","tag-russia"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1080","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=1080"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1080\/revisions"}],"predecessor-version":[{"id":1081,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1080\/revisions\/1081"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=1080"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=1080"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=1080"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}