Tag: russia
-
UK issues alert over Russian zero-click email attacks
First seen on scworld.com Jump to article: www.scworld.com/brief/uk-issues-alert-over-russian-zero-click-email-attacks
-
The OpenAI Models That Hacked Hugging Face Were ‘Active on the Internet’ for Days
Plus: Russian hackers are trying to steal US nuclear scientists’ emails, the State Department bans known scammers from entering the United States, and more. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-the-openai-models-that-hacked-hugging-face-were-active-on-the-internet-for-days/
-
Russian Espionage Hackers Hit Zimbra With Half-Click Attacks
Tags: attack, cyberespionage, cybersecurity, data, email, espionage, hacker, malicious, russia, update, vulnerabilityViewing Malicious Email in Vulnerable Webmail Client Triggers Data-Stealing Attack. Russian cyberespionage hackers are targeting a vulnerability in Zimbra Collaboration Suite – a patch is available – that enables them to execute a malicious, data- and email-stealing script simply if a user of a vulnerable client opens their email, warn Western cybersecurity agencies. First seen…
-
Russian hackers exploit unpatched Zimbra servers to steal emails
Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/laundry-bear-zimbra-vulnerability-cve-2025-66376/
-
Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks
Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims. First seen on hackread.com Jump to article: hackread.com/russian-hackers-zimbra-0-day-steal-emails-link-clicks/
-
UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations
UAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis. CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting WinRAR vulnerabilities and using phishing…
-
Russian APT Laundry Bear perfects zero-click phishing attack
A newly identified Russian state threat actor is using a novel zero-click phishing technique, likely developed with the help of an AI, to target Western users of Zimbra software products First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645968/Russian-APT-Laundry-Bear-perfects-zero-click-phishing-attack
-
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
Tags: advisory, apt, cybersecurity, email, exploit, flaw, government, group, infrastructure, international, russiaUS agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers. The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT…
-
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems.The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed…
-
Russian LAUNDRY BEAR Hackers Exploit Zimbra Zero-Day to Steal 90 Days of Emails
Tags: advisory, cyber, cybersecurity, defense, email, espionage, exploit, government, group, hacker, russia, technology, threat, vulnerability, zero-dayRussian state-supported threat actors, known as LAUNDRY BEAR, have exploited a zero-day vulnerability in the Zimbra Collaboration Suite to steal up to 909,090 days’ worth of emails from targeted organizations across Western countries. A joint cybersecurity advisory, AA26-204A, issued on July 23, 2026, warns that this espionage-focused group has targeted government, defense, energy, technology, education,…
-
Russian TA488 Exploits Zimbra CVE-2025-66376 to Target Government Mail Servers
Russian-aligned TA488 exploited Zimbra CVE-2025-66376 in a half-click attack. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/russian-ta488-exploits-zimbra-cve-2025-66376-to-target-government-mail-servers/
-
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
A state-sponsored threat group, dubbed Laundry Bear, sends half-click phishing emails that require a victim only to open or preview the message. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets
-
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.The NSA, CISA…
-
International alert spotlights Russia-linked attacks on Zimbra webmail
A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said. First seen on therecord.media Jump to article: therecord.media/zimbra-webmail-zero-click-phishing-russia-laundry-bear
-
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. First seen on cyberscoop.com Jump to article: cyberscoop.com/russian-laundry-bear-zimbra-exploit/
-
Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/
-
Russia-backed threat actor targets Western organizations in phishing campaign
The threat actor exploited a zero-day flaw in Zimbra to exfiltrate months of emails and other sensitive information. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/russia-threat-actor-western-organizations-Zimbra-phishing/826029/
-
Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations
International agencies issue joint alert over state-backed campaign exploiting a critical vulnerability in the Zimbra Collaboration Suite First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-hackers-zero-click/
-
TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits
At a Glance Actor or group TA488 (Void Blizzard, Laundry Bear) and TA458 (Operation RoundPress), both Russia-aligned Activity First seen on securityonline.info Jump to article: securityonline.info/half-click-exploits-webmail/
-
Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday – and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. First seen on grahamcluley.com Jump to article: grahamcluley.com/smashing-security-podcast-477/
-
Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military
Researchers found Chinese and Russian SDKs in Android apps marketed to U.S. military users, highlighting software supply chain and enterprise privacy risks. The post Third-Party SDKs Raise Privacy Questions for Apps Marketed to U.S. Military appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-android-sdk-supply-chain-privacy-military-apps/
-
Threat Actor Turns Claude Opus Into Automated AI-Powered Penetration Testing Platform
A Russian-speaking threat actor known as “Trim” has reportedly transformed Anthropic’s Claude Opus into the central component of an automated, AI-powered penetration testing platform. This development highlights the rapid repurposing of advanced AI models for offensive security operations. According to research by Cato CTRL, Trim progressed from sharing jailbreak instructions on a Russian cybercrime forum…
-
North Korea’s IT worker scheme funds Russia’s war effort, report finds
First seen on scworld.com Jump to article: www.scworld.com/brief/north-koreas-it-worker-scheme-funds-russias-war-effort-report-finds
-
US federal workers mandated to use app with Russian-founded vendor’s code
Tags: russiaFirst seen on scworld.com Jump to article: www.scworld.com/brief/us-federal-workers-mandated-to-use-app-with-russian-founded-vendors-code
-
HelloNet campaign abuses ViPNet update mechanism to target Russian organizations
First seen on scworld.com Jump to article: www.scworld.com/brief/hellonet-campaign-abuses-vipnet-update-mechanism-to-target-russian-organizations
-
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
A Russian-speaking actor, Trim, dismantled publicly available frontier models and integrated them with offensive security tools. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/hacker-ai-jailbreaks-offensive-attack-platform
-
North Korea’s IT worker scheme funds Russia’s war effort
DTEX researchers found a series of transactions in a payment wallet showing North Korean IT worker salaries flowing into sanctioned entities that support the regime’s military programs. First seen on cyberscoop.com Jump to article: cyberscoop.com/north-korea-it-worker-scheme-funds-russia-war-ukraine/
-
Russian Hacker Turns Jailbroken Claude Into Pentest Platform
Russian-speaking actor Trim built a commercial offensive AI pentest tool on jailbroken Claude models First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/trim-jailbroken-claude-ai-pentest/
-
Apps targeted at US troops contain Chinese and Russian code
More than one-eighth of apps analyzed contained foreign code. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/apps-targeted-at-us-troops-contain-chinese-and-russian-code/
-
European Password Manager Passwork Shares Codebase and Updates With FSTEC-Certified Russian Firm
Passwork Europe, a Spain-based password manager used by European public sector bodies, universities, and private organizations, is facing scrutiny after an investigation led by OCCRP uncovered technical and historical connections to a Russian counterpart certified by Russian state agencies. The investigation found that Passwork Europe S.L. and Russia’s Passwork LLC share a common codebase origin,…

