Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Russia-Linked DRILLAPP Backdoor Targets Ukrainian Entities via Microsoft Edge
A new cyberespionage campaign has been identified, targeting Ukrainian organizations with a backdoor named DRILLAPP, attributed to Russian threat actors, specifically the Laundry Bear group. The campaign employs…
3 articles · Updated March 18, 2026 -
Russian Hackers Target Zimbra Users, Compromise Hundreds of Emails
A coordinated cyber espionage campaign by the Russian hacker group Laundry Bear has led to the theft of hundreds of emails from Zimbra users. The campaign, which initially focused on Ukraine, has since expanded to…
4 articles · Updated July 24, 2026 -
Russia and China Intensify Cyber Threats Amid Geopolitical Tensions
The Dutch intelligence agency AIVD's 2025 report indicates that Russia is preparing for a long-term confrontation with Western nations, marking the most severe threat environment in 80 years. The report highlights an…
2 articles · Updated April 26, 2026 -
US Charges Russian Hacker for Facilitating Void Blizzard Cyber Espionage Campaign
Denis Obrezko, a 36-year-old Russian national, was arrested in Thailand and extradited to the US, where he faces charges for facilitating a cyber espionage campaign linked to the group Void Blizzard. This group has…
8 articles · Updated June 10, 2026 -
Russian Cyber Espionage Suspect Pleads Not Guilty in US Court
Denis Obrezko, a 36-year-old Russian man and former FSB agent, pleaded not guilty to charges related to a cyber espionage campaign targeting Western organizations. Extradited from Thailand, he faces accusations of…
12 articles · Updated July 9, 2026 -
TA488 Exploits Outlook Web Access CVE-2026-42897 in New Campaign
TA488 has launched a campaign exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access (OWA). This vulnerability, disclosed by Microsoft on May 14, 2026, allows attackers to deploy a persistent…
3 articles · Updated July 30, 2026 -
Russian Hackers Target Ukrainian Military with Charity-Themed Malware Campaign
Between October and December 2025, Ukrainian Defense Forces were targeted by a cyberattack disguised as a charitable foundation. The attack, attributed to the Russian group Void Blizzard (Laundry Bear), installed…
3 articles · Updated January 14, 2026 -
Zimbra urges customers to patch critical web client XSS flaw
18 articles · Updated July 10, 2026
-
Cyberattacks on Ukraine's Defense Forces Linked to Russian Group
CERT-UA reported new cyberattacks involving PLUGGYAPE malware targeting Ukraine’s defense forces. The attacks are attributed with medium confidence to the Russian-linked group Void Blizzard. This incident highlights…
3 articles · Updated January 14, 2026
Recent Intelligence Reports
- Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover — Csoonline · July 30, 2026
- 826029 — www.cybersecuritydive.com · July 25, 2026
- Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries — Cyberscoop · July 24, 2026
- ASD, National Cyber Security Coordinator warn of ongoing Russian phishing campaign — Defenceconnect.Au · July 24, 2026
- Supo Warns Again: Russian Cyber Spies Are Attacking Email Systems — yle.fi · July 24, 2026
- US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers — Securityaffairs.Co · July 24, 2026
- Russian attackers exploit zero-click vulnerability in Zimbra — Heise.De · July 24, 2026
- Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero — Gbhackers · July 24, 2026