CVE-2025-66376 is a vulnerability tracked across 6 threat clusters and 23 intelligence report mentions on ThreatCluster. First observed March 18, 2026; most recent activity July 25, 2026.
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
A Russian state-linked advanced persistent threat (APT) has targeted a Ukrainian government agency through a cross-site scripting (XSS) vulnerability in the Zimbra Collaboration Suite, identified as CVE-2025-66376. The…
Russian threat actors TA488 and TA458 are exploiting vulnerabilities in webmail servers, specifically targeting Ukrainian entities and government sectors. TA488 utilizes a half-click exploit via CVE-2025-66376 in Zimbra…
Amazon Web Services (AWS) has implemented a new security feature to combat S3 Bucket Namesquatting, also known as Bucketsquatting, which allows attackers to exploit predictable naming conventions in AWS bucket names.…