Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Iranian Hackers Target Siemens and Schneider Industrial Systems

July 23, 2026

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

July 23, 2026

Russian Hackers Exploit New ‘Zero-Click’ Attack

July 23, 2026
Facebook X (Twitter) Instagram
Thursday, July 23
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Russian Hackers Exploit New ‘Zero-Click’ Attack
News

Russian Hackers Exploit New ‘Zero-Click’ Attack

Team-CWDBy Team-CWDJuly 23, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Russian state-supported hackers are targeting organizations with a new attack technique using a Zero-Click method which doesn’t require users to interact with the phishing email.

The campaign is designed to compromise networks and gain persistent access, a joint advisory from western cyber intelligence agencies has warned.

Issued on July 23, the alert warned that state-backed threat actors working on behalf of Russia have been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025.

Organizations known to be targeted by these espionage attacks have been identified in the defense, government, education, energy, law enforcement, media, NGO and technology sectors.

The joint advisory has been issued by the UK National Cyber Security Centre, US agencies including Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency and the FBI, along with cyber and intelligence agencies from the other Five Eyes nations (Canada, Australia and New Zealand), as well as European agencies.

The campaign has been attributed to cyber espionage operation which has been linked to Russia dubbed Laundry Bear, also known as Void Blizzard and UAC-0190.

The Laundry Bear campaign exploits a zero-day vulnerability in ZCS (CVE-2025-66376) which was publicly disclosed in November 2025 and uses a zero-click exploit coined “beehive” to steal emails and other sensitive data.

Unlike traditional phishing campaigns which require a user to be socially engineered into taking an action, such as clicking a link or opening a file, the Laundry Bear campaign leverages the vulnerability to exploit a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service.

If the exploit is successful, the attackers look to exfiltrate at least the last 90 days of emails from the server, as well as other sensitive information. Laundry Bear also attempts to maintain persistence on the network of the compromised victim by secretly stealing passwords and circumvent multi-factor authentication protections through session tokens.

Organizations which use ZCS have been urged to take immediate action to patch the critical vulnerabilities and improve their network monitoring capabilities.

“This phishing campaign demonstrates how hostile actors will ruthlessly adapt techniques and exploit vulnerable technology in pursuit of their aims to steal sensitive information from Western organizations,” said Beth Hopkins, COO of the NCSC.

“With our international partners, we strongly encourage organizations to familiarize themselves with the ‘zero-click’ techniques described in the advisory which could be used against other platforms, and act on the mitigation advice,” she added.

In addition to immediately patching vulnerability, system administrators have been advised to be on the lookout for suspicious activity.

The advisory also recommends that organizations should consider using a third-party authentication service that supports passkeys for authentication to mediate access to ZCS and other services that do not natively support passkeys. Doing this can help eliminate the possibility of threat actors exploiting stolen credentials to access servers.

The alert also warned that technical analysis of the campaign indicated that AI played a role in the development of a simple codebase for the operation. This comes after intelligence agencies have warned about how malicious threat actors could harness AI in their campaigns.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleFake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
Next Article GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Team-CWD
  • Website

Related Posts

News

Iranian Hackers Target Siemens and Schneider Industrial Systems

July 23, 2026
News

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

July 23, 2026
News

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

July 23, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

It’s all fun and games until someone gets hacked

September 26, 2025

What’s at stake if your employees post too much online

December 1, 2025

Mobile app permissions (still) matter more than you may think

February 27, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.