WorldTimes of India
Russian hackers exploited Zimbra bug to steal emails
in5points
A Russian government-backed hacking group called Laundry Bear exploited a vulnerability in the Zimbra email platform to steal emails without requiring victims to click links or open attachments, using a 'half-click exploit'.
The campaign initially targeted Ukraine and later expanded to users in the United States and other NATO member states, according to a joint advisory from US, UK, Canada, Australia, New Zealand, and European agencies.
Proofpoint stated the exploit allowed compromise when a user merely opened an email, requiring no social engineering, and the vulnerability has since been patched.
British Security Minister Dan Jarvis noted the attackers tested methods on Ukrainian victims before targeting NATO members.