UK NCSC and Partners Publish International Alert on Russian State-Supported Zero-Click Zimbra Zero-Day Campaign
A year-long Russian state-supported zero-click Zimbra campaign, exposed this week by NCSC UK and partners across some 16 nations — a defender review for any organization still running unpatched Zimbra.
Key Takeaways
|
A year-long Russian state-supported zero-click Zimbra campaign, named and attributed by NCSC UK and partners across some 16 nations — the defender story is patch-and-verify, not the exploit itself.
LONDON — The UK's National Cyber Security Centre (NCSC UK) and partners across roughly 16 nations on July 23, 2026 published a joint international alert exposing a Russian state-supported "zero-click" phishing campaign that reportedly ran for about a year against Western organizations running unpatched Zimbra webmail servers. The advisory attributes the activity to a Russian state-supported cluster it calls LAUNDRY BEAR — also tracked in industry reporting as Void Blizzard — and says the actors reportedly harvested mailbox contents and two-factor-authentication (2FA) codes.
The alert was coordinated among government cyber agencies, with US signatories including CISA, the NSA and the FBI joining the NCSC and more than a dozen other national partners. As reported by Dark Reading and The Register, the campaign leaned on a flaw in Zimbra Collaboration Suite rather than on a link or attachment a user had to click. This piece summarizes what the joint alert documents and what it asks defenders to do — patch, verify, and review indicators — without reconstructing how the technique works.
| At a Glance | |
|---|---|
| Field | Details |
| What | Joint international alert on a Russian state-supported "zero-click" Zimbra campaign |
| Who published | NCSC UK and partners across ~16 nations; US signatories include CISA, NSA and FBI |
| Attributed actor | LAUNDRY BEAR, per the advisory (also tracked as Void Blizzard) |
| Vulnerability | CVE-2025-66376 in Zimbra Collaboration Suite webmail |
| Reported duration | About a year before disclosure |
| Reported data taken | Mailbox contents and 2FA codes, per reporting |
| Reported targets | US defense, government, education, energy, media, NGOs, tech; Ukraine and NATO-aligned orgs |
| Patch status | Zimbra fixed the flaw on November 6, 2025; added to CISA KEV in March 2026 |
| Disclosure date | July 23, 2026 |
What the Joint Alert Documented
According to the NCSC UK advisory and coordinated partner statements, a Russian state-supported cluster the alert names LAUNDRY BEAR conducted a phishing campaign against organizations running Zimbra Collaboration Suite, the open-source webmail and collaboration platform. The through-line the agencies emphasize is that the operation reportedly required no click on a malicious link or attachment — the reason multiple governments and outlets have described it as "zero-click." The campaign reportedly ran for roughly a year before this week's disclosure.
The alert ties the activity to CVE-2025-66376, a vulnerability in Zimbra's webmail interface. In defender terms, the salient facts are that the flaw is in an internet-facing mail product, that Zimbra shipped a fix on November 6, 2025, and that CISA later added the vulnerability to its Known Exploited Vulnerabilities catalog in March 2026. Reporting from The Hacker News indicates the actors used the access to read mailbox contents and to harvest 2FA codes; the advisory describes a custom aggregation-and-exfiltration capability the actors used against affected servers. The CyberSignal is deliberately not reproducing the mechanics — the defender-relevant facts are the affected product, the fixed version, and the published indicators.
Reported targets, per partner statements, span US organizations across defense, government, education, energy, media, NGOs and technology, alongside Ukraine and other NATO-aligned bodies. The consistent characterization across signatories is espionage: covert collection of email data rather than disruption or extortion.
The "Zero-Click" and Year-Long Framing in Defender Terms
Two phrases from the alert will travel fastest — "zero-click" and "year-long" — and both are worth translating for a defender team rather than taking at face value. "Zero-click" means the campaign did not depend on the usual human step of clicking a link or opening an attachment; the exposure sat in how a vulnerable Zimbra webmail instance handled certain messages. Some researchers have noted the interaction is closer to "half-click" in that a message still had to be rendered, but the defender-relevant point is the same: user-awareness training is not the primary control here. Patching and hardening the mail server is.
"Year-long" is the detail that should reframe incident scoping. If exploitation reportedly predates the fix and stretched across many months, then for an organization that ran an unpatched Zimbra instance during that window, the relevant question is not only "are we patched now" but "what happened while we were exposed." That shifts effort toward retrospective review — mailbox access, 2FA-code exposure, and the published indicators — rather than treating the patch as the end of the matter. Neither framing requires understanding the exploit; both point at the same workflow: confirm the fixed version is deployed, assume webmail was reachable during the exposure window, and look backward using the agencies' indicators.
Where This Fits in the Russian Espionage Pattern
The alert lands in a run of coordinated Western attribution of Russian state-supported cyber activity that The CyberSignal has tracked closely. The naming of Void Blizzard is itself a thread: US prosecutors have already moved against an individual charged in connection with Void Blizzard activity, so this week's alert extends a cluster already on Western radar rather than introducing a new one. It also fits the NCSC's own framing of the threat environment, set out when the agency warned that hostile states threaten a large share of UK critical infrastructure.
The espionage character rhymes with other Russian state-supported operations the site has covered — from a Russian nation-state botnet built around Signal Desktop to a WinRAR flaw exploited by Russia-aligned groups against Ukraine. What is distinctive here is the breadth of the coalition: a joint alert spanning roughly 16 nations, with US, UK, Dutch, Australian and Canadian agencies among the signatories, aimed less at surprising the actor than at pushing exposed organizations to close a specific, already-patched hole.
Defender Posture for Organizations Running Zimbra
For any organization operating Zimbra, the alert converts into a short, concrete checklist. First, confirm the deployment is on a version that includes the November 6, 2025 fix for CVE-2025-66376; the flaw's presence in CISA's KEV catalog makes patching a baseline expectation for US federal agencies and a strong signal for everyone else. Second, treat internet-facing webmail as a priority attack surface: minimize its exposure, restrict administrative interfaces, and verify that logging is enabled and retained long enough to support a look-back across the reported exposure window.
Third, assume the possibility of prior access rather than only preventing future access. Because the campaign reportedly ran for about a year and reportedly reached mailbox contents and 2FA codes, organizations that ran unpatched Zimbra should consider credential and 2FA-secret rotation for potentially affected accounts, and review whether any harvested session material could still be valid. None of this requires knowing how the flaw was triggered; all of it follows from the alert's own facts.
Detection-Engineering Review per Published Indicators
The joint alert and its partner publications include indicators of compromise and detection guidance, and the defender move is to route those into monitoring rather than to characterize the actor's tooling. Reporting from Help Net Security and CyberScoop notes the actors relied on custom aggregation-and-exfiltration capability, which is the kind of detail worth translating into host- and network-level detections against the published artifacts.
Practically, that means loading the advisory's indicators into SIEM and EDR content, hunting historically across the reported exposure window rather than only forward from the patch date, and prioritizing telemetry around Zimbra hosts and the identity systems that issue and validate 2FA. The goal is not to model the campaign but to answer a narrow question with the agencies' own artifacts: did anything matching these indicators touch our environment while it was exposed?
Open Questions
Several specifics remain unresolved at publication, and The CyberSignal is not filling them in. Public totals of confirmed victims are not established in the material reviewed, and the full membership and exact count of the coalition behind the alert are reported with some variation across outlets. The precise attribution of LAUNDRY BEAR to a specific Russian intelligence service, as opposed to a named actor cluster, is likewise something the agencies frame carefully; this piece follows the advisory's own naming and does not assert a sponsoring service.
Other questions are about impact rather than mechanics: how many exposed organizations were actually accessed, and how completely the published indicators capture the activity. These will sharpen as agencies, Zimbra and independent researchers publish more. The reporting frames this as a defender-oriented disclosure of an already-patched flaw under active exploitation — which is why the guidance above centers on patching, verification and indicator-driven review.
The CyberSignal Analysis
The reported facts above come from the joint alert and its reporting; what follows is The CyberSignal's editorial reading. None of the judgments below are new reported facts.
Signal 01 — The Story Is Patch Latency, Not the Zero-Click Label
The "zero-click" framing is what will carry the headline, but our reading is that the load-bearing detail is time. The flaw was fixed on November 6, 2025 and added to CISA's KEV catalog in March 2026, yet the campaign reportedly ran for about a year and this coordinated alert only arrived in July. The exposure that mattered lived in the gap between a fix being available and organizations actually deploying it on an internet-facing mail server.
That reframes the defender lesson away from the exotic and toward the familiar: the organizations most at risk were not those who failed to understand a novel technique, but those whose webmail patch cadence lagged. Seen that way, this alert is less a new-capability warning than a reminder that unpatched, internet-facing collaboration software remains a first-choice target for state-supported espionage.
Signal 02 — Coalition Attribution Is Doing Deliberate Work
A joint alert spanning roughly 16 nations, naming a specific Russian state-supported cluster, is not primarily an intelligence surprise — the actor was already tracked as Void Blizzard, already the subject of US prosecution. Our assessment is that the coordination itself is the message: a broad Western coalition publicly aligning on attribution and on a single remediation ask raises the diplomatic and operational cost of the activity while giving exposed organizations unambiguous cover to prioritize the fix.
For defenders, the practical value of that coalition is consolidation: instead of parsing several vendor accounts, an organization gets one government-backed set of indicators and one clear directive. The useful posture is to treat the joint attribution as a prioritization signal and act on the shared indicators quickly.
Signal 03 — Webmail Is Identity Infrastructure Now
The detail we find most durable is what the actors reportedly went after: not just email, but 2FA codes. Our view is that this reframes a mailbox from a store of messages into a piece of identity infrastructure — a place where authentication material accumulates and can be turned into wider access. That is why a mail-server flaw warrants credential and 2FA-secret rotation, not just a patch.
The organizations best positioned to absorb this are those that already treat their mail platform as a tier-zero identity asset — monitored, tightly patched, and wired into the same rotation and detection discipline as directory services. We would treat this alert as a prompt to ask a blunt internal question: if our webmail were reachable and unpatched for months, what authentication secrets would have been sitting inside it — and have we rotated them yet?