
Fake Resumes + Watering Holes Hit AnySign4PC Users
A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…
Government agencies say a Russian-linked group sent specially crafted HTML emails that exploit a Zimbra webmail flaw, so simply viewing the message can trigger data theft, no click required. The campaign has targeted multiple Western sectors since July 2025 and focuses on stealing email content and login information to maintain access.
A Russian-linked group tracked as Laundry Bear, also known as Void Blizzard, sent specially crafted HTML emails that exploit a cross-site scripting flaw in Zimbra webmail, tracked as CVE-2025-66376. Unlike most phishing, this campaign did not depend on the victim clicking a link or opening an attachment. Simply viewing the email in a vulnerable Zimbra client was enough to trigger malicious code execution. Once triggered, the attackers focused on covertly acquiring email data and used stolen credentials to maintain access, modifying account preferences and creating new application passcodes to keep their foothold.
This attack succeeded because it removed the usual human decision point that awareness training targets. Most phishing defenses teach people to scrutinize links, sender addresses, and attachments before acting. Here, the exploit fired the moment the email was rendered for viewing, meaning caution about clicking provided no protection. The campaign also relied on an unpatched software vulnerability rather than solely on deception, combining a technical flaw with the routine act of checking email, something nearly every employee does many times a day without a second thought.
Because this attack required no user interaction beyond viewing a message, technical controls and rapid patching matter as much as awareness. Organizations should prioritize applying the Zimbra patch and, where advised by security teams, temporarily limit use of the affected webmail client. Staff across all roles, not just IT and email administrators, should still be encouraged to report unexpected or unusual emails, since early reporting can help security operations identify a campaign before it spreads further. Helpdesk and IT teams should also actively monitor for the account-level indicators described above, since these can reveal compromise even when the initial email itself looked unremarkable. Given the broad range of affected sectors, including defense, government, education, energy, law enforcement, media, and NGOs, this type of zero-click email threat is relevant to nearly any organization relying on webmail platforms.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
No. According to the joint alert, the attack triggers as soon as the victim views the malicious HTML email in Zimbra webmail, with no need to click a link or open a file.
Reported stolen data includes up to 90 days of emails, passwords, global address lists, two-factor authentication tokens, and application passcodes.
The campaign has targeted organizations across defense, government, education, energy, law enforcement, media, NGOs, and technology sectors since July 2025.
Agencies recommend limiting use of the Zimbra webmail client until organizations apply the available patch, and monitoring for signs of account takeover such as changed preferences or newly created app passcodes.
Imagine this: you just open your inbox, glance at an email, and boom, your account’s already compromised. That’s the Zimbra webmail bug, CVE-2025-66376. Laundry Bear, also called Void Blizzard, sent malware-laden HTML emails that exploit a Zimbra XSS flaw. Just viewing the message in Zimbra can silently dump 90 days of your email, passwords, 2FA tokens, and app passcodes. Here’s the nasty part: there might be no link, no attachment, nothing obvious. The only clue is the context, an unexpected HTML email in Zimbra, and then weird account behavior: settings changed, new app passwords, logins you don’t recognize. If you use Zimbra and see a weird HTML email or odd changes in your mailbox, don’t ignore it, hit the phishing or report button and call IT. Let them know, "This might be that Zimbra CVE-2025-66376 thing."

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

CERT-UA reports a real phishing campaign linked to Russia-aligned actor UAC-0099 targeting Ukrainian organizations. Victims receive an email with an image…

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude…

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to…

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a…