Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. A Russian state-supported campaign used CVE-2025-66376 to run JavaScript when a victim opened or previewed a malicious email in a vulnerable Zimbra webmail client. The Australian Cyber Security Centre says the activity was primarily associated with LAUNDRY BEAR; Proofpoint tracks the actor as TA488/Void Blizzard and reports Ukrainian targets. Zimbra patched the flaw in November 2025.

What was the Zimbra vulnerability?

CVE-2025-66376 was a zero-day when the campaign first used it. The flaw was in how Zimbra handled CSS @import directives in email content: improper sanitization allowed JavaScript to execute in the webmail context. The Australian Cyber Security Centre advisory, published 24 July 2026, says the National Vulnerability Database published the CVE on 5 January 2026.

The campaign had been active from at least July 2025, according to the Australian Cyber Security Centre and Proofpoint. That timeline means the exploit was being used before the November 2025 patch and before the CVE appeared in the NVD.

Could simply opening a Zimbra email trigger it?

Yes—on a vulnerable Zimbra client, viewing or previewing the malicious message could be enough. The JavaScript was embedded in the message’s HTML body, so the victim did not need to click a link or open an attachment. This is sometimes called a “half-click” or view-based exploit.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Execution in the webmail context gave the attacker a route to pursue mailbox information and credentials. The Australian advisory says the Ulej capability attempted to obtain the victim’s last 90 days of email, the organization’s global address list, and other sensitive information. The advisory and Proofpoint also report credential theft; Proofpoint observed persistence on Zimbra systems.

Who was targeted, and how does this relate to other Russian webmail attacks?

Proofpoint reports that TA488 targeted Ukrainian entities alongside US government, high-science, nuclear, and defense-industrial targets. A separate ESET report documents Sednit’s Operation RoundPress, an earlier campaign that expanded to Zimbra as well as other webmail products. These reports describe distinct campaigns; the shared use of webmail exploits does not establish that they were the same operation.

Rank #2
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Comparison LAUNDRY BEAR / TA488 (from at least July 2025) Sednit / Operation RoundPress (October 2024–March 2025 reporting period)
Product and vulnerability Zimbra Collaboration Suite; CVE-2025-66376, a CSS @import sanitization flaw (Australian Cyber Security Centre; Proofpoint). RoundPress expanded from Roundcube to Horde, MDaemon, and Zimbra; the cited ESET report does not state a CVE for this activity.
Interaction and delivery JavaScript embedded in an email’s HTML could run when the message was opened or previewed; no link click or attachment opening was required (Proofpoint). ESET describes spearphishing lures and SpyPress.ZIMBRA JavaScript payloads; whether opening alone was sufficient is not stated in the cited ESET report.
Data sought Ulej attempted to collect the last 90 days of email, the global address list, and other sensitive information; credential theft was also reported (Australian Cyber Security Centre; Proofpoint). SpyPress.ZIMBRA collected mailbox messages and contact information and sent them to command-and-control infrastructure (ESET).
Persistence and patch status Proofpoint observed persistence on Zimbra systems. Zimbra patched CVE-2025-66376 in November 2025; the cited sources do not specify affected or fixed version numbers. Persistence behavior and patch or mitigation status are not stated in the cited ESET report.
Victims and geography Proofpoint names Ukrainian entities, as well as US government, high-science, nuclear, and defense-industrial targets. ESET says several campaigns targeted defense companies in Bulgaria and Ukraine; its 19 May 2025 announcement says Ukraine had the greatest intensity of attacks against critical infrastructure and governmental institutions in the covered period.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should Zimbra administrators reduce risk?

  1. Apply current Zimbra security updates. The flaw was patched in November 2025, but the available reporting does not identify fixed release numbers. Check Zimbra’s official security advisories for the version in use and install the applicable latest security update.
  2. Enable multifactor authentication where supported. MFA can make stolen passwords less useful, though it does not prevent malicious code from running in a vulnerable webmail client.
  3. Monitor accounts and systems for suspicious activity. Look for unauthorized access, unexpected mailbox activity, credential misuse, and signs of persistence on Zimbra systems.
  4. Ask users to report suspicious messages. Training remains useful for phishing, but users should not treat “I didn’t click anything” as proof that a message was harmless: this exploit could trigger on viewing.

The Australian Cyber Security Centre notes that use of a zero-day in this campaign showed how an emerging threat group could operationalize a novel exploit. The reports do not provide an independent victim count or prevalence statistic.

Quick Recap

Bestseller No. 1
Bestseller No. 2
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
Made in USA - Proudly produced in Ohio by a Veteran-owned business
$22.99
Bestseller No. 3
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Large)
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Large)
Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches); Durable material imported from Japan.
$50.00
Bestseller No. 4
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Medium)
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Medium)
Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches); Durable material imported from Japan.
$62.49
Rank #4
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Medium)
  • Looks like a real book, a good choice to be hidden that will coordinate with your books on shelf.
  • Combination diversion book safe is locked by security code( 3-number combination lock), No need to worry about losing key
  • Enough space to hide cash, coins, jewelries, watch, passport, paper bill and other valuable items.
  • Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches)
  • Durable material imported from Japan.
Rank #3
Nakabayashi Co.,Ltd. Dictionary Book Secret Security Box with Number Combination Key(Large)
  • Looks like a real book, a good choice to be hidden that will coordinate with your books on shelf.
  • Combination diversion book safe is locked by security code( 3-number combination lock), No need to worry about losing key by owing to Dial key
  • Enough space to hide cash, coins, jewelries, watch, passport, paper bill and other valuable items.
  • Outer Dimensions: W2.17*D7.40*H10.0(inches); Inner Dimensions: W1.97*D5.90*H9.53(inches)
  • Durable material imported from Japan.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.