
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
A newly identified Russia-linked threat actor (“Laundry Bear”) is targeting Western organisations with a zero-click technique that can compromise Zimbra webmail simply by viewing a malicious email. The campaign has reportedly stolen sensitive data across multiple sectors and may evolve to target other email platforms as organisations patch.
Laundry Bear, a threat actor linked with confidence to the Russian state, has been targeting Western organisations since at least 2024. Its most notable technique, called beehive or Ulej, is a zero-click phishing method aimed at Zimbra Collaboration Suite (ZCS) webmail. Rather than relying on a victim clicking a malicious link, the technique exploits CVE-2025-66376, a stored cross-site-scripting vulnerability in the ZCS classic user interface. By abusing CSS @import directives embedded in HTML email content, an attacker can trigger compromise the moment a target simply views the email in a vulnerable webmail client.
Earlier activity attributed to the same group involved a different approach: a malicious website masquerading as a European Defence and Security Summit registration portal, used to lure targets in defence and government circles into submitting information through a fake registration flow.
The core reason this technique is effective is that it bypasses the standard advice given in most security awareness training. Employees are typically taught to avoid clicking suspicious links or opening unexpected attachments, but a zero-click exploit does not require any of that. Merely viewing an email in a vulnerable version of ZCS webmail is sufficient to trigger compromise, which sidesteps the usual human decision point that awareness training is designed to influence.
The technique also targeted a broad range of sectors, including government, defence, education, energy, law enforcement, media, and NGOs, giving it a wide potential impact across organisations that rely on Zimbra webmail.
Organisations should prioritize rapid patching of internet-facing email systems, since Zimbra patched this specific flaw in November 2025 and the NCSC has urged any unpatched users to update immediately. Layered technical defences matter because patching alone will not stop every variant of this kind of attack.
Security teams should also assume the beehive technique could be adapted to exploit other email platforms and vulnerabilities beyond Zimbra, so monitoring and response planning should not be limited to a single vendor. Finally, awareness programs should be updated to reflect that some attacks require no click at all, reinforcing the need for technical controls alongside training rather than relying on user behavior as the sole defense.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It is a technique called beehive that exploits a stored cross-site-scripting flaw in Zimbra Collaboration Suite webmail, allowing compromise just from viewing a malicious HTML email.
No. Simply viewing the malicious email within a vulnerable version of ZCS webmail is enough to trigger compromise.
Yes, Zimbra patched the vulnerability, tracked as CVE-2025-66376, in November 2025, and the NCSC urges any unpatched users to update immediately.
Yes, the underlying beehive technique could reportedly be adapted to exploit other vulnerabilities and email platforms.
You know that Zimbra webmail tab you leave open all day? Laundry Bear can hijack it just because you *look* at the wrong email. They’re running a zero-click attack called Beehive against Zimbra’s classic UI. Subject line looks normal, like “Updated meeting agenda, please review,” but the HTML hides a CSS @import trick for CVE-2025-66376. You don’t click anything, just viewing it can compromise your mailbox. Same group also spun up a fake European Defence and Security Summit registration site. The page screams “Register now for the European Defence and Security Summit,” but the URL is a random domain that doesn’t match any real organiser. Here’s the move: if you use Zimbra, don’t just avoid clicks, make sure your Zimbra is fully patched past the November 2025 fix, and report any odd HTML-heavy emails to security.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

Attackers abused Anthropic’s Claude “Artifacts” publishing feature to host a convincing fake Claude download page on the real claude.ai domain. Victims found…

ClickFix is a fast-growing social engineering tactic that gets people to run malware themselves by pasting a command into Windows Run or macOS Terminal.…

Researchers report an active phishing-as-a-service operation, Forg365, that targets Microsoft 365 users with document/payment-themed lures and techniques that…

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…