A joint advisory published on 24 July by the ACSC, CISA, FBI, NSA and cyber agencies from 15 countries confirms that Russian state-backed group Laundry Bear has been exploiting Zimbra Collaboration Suite to steal email data from government and private-sector organisations — including in Australia.
The attack targets CVE-2025-66376, a cross-site scripting flaw in Zimbra’s webmail client. What makes it dangerous is that it’s zero-click: a specially crafted email executes malicious JavaScript the moment a user opens it. No link to click, no attachment to download. If you’re running an unpatched Zimbra server, simply reading an email can hand over your credentials and two-factor codes.
The vulnerability was patched in November 2025, but the advisory makes clear that many organisations still haven’t applied the fix — and Laundry Bear has been exploiting it since at least July 2025.
Why This Matters for Australian Businesses
We still see Australian SMBs running self-hosted email platforms — Zimbra, older Exchange, and legacy mail servers that someone set up years ago and nobody’s touched since. These systems sit directly on the internet, and when a vulnerability drops, there’s no cloud provider rolling out the patch for you. You’re on your own.
This advisory is a concrete example of why that’s risky. State-sponsored groups are scanning for exactly these systems, and the gap between a patch being available and an attacker exploiting the flaw can be less than a week.
If your organisation is still running self-hosted email, the calculus has shifted. Cloud-hosted platforms like Microsoft 365 handle patching, authentication hardening, and threat detection at a scale that no SMB can match on-prem. That doesn’t mean cloud is set-and-forget — it still needs proper configuration — but you’re no longer one missed patch away from a state-sponsored intrusion.
What to Do Now
If you’re running Zimbra, patch to the latest version immediately. If you’re unsure what email platform your business is on, or whether it’s fully patched, get in touch with our team and we’ll check it for you. This one’s too serious to leave until Monday.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
