Russian hackers can steal emails without a click

Opening an unexpected email can feel relatively harmless when you avoid its links and attachments.However, a Russian hacking campaign has turned that familiar safety advice on its head.CISA says the Russian state-sponsored group Laundry Bear can compromise certain email accounts when someone simply opens or previews a malicious message.
The attack targets organizations running unpatched versions of the Zimbra Collaboration Suite.Once the email appears, hidden code can collect passwords, authentication data and as much as 90 days of messages.You may never see a warning or realize that anything happened.The Cybersecurity and Infrastructure Security Agency issued the warning with the National Security Agency, FBI and cyber authorities from several allied countries.
The agencies say the group has successfully targeted more than 10 Western organizations since July 2025.INVESTIGATORS BELIEVE IRANIAN HACKERS ARE LIKELY BEHIND CYBERATTACK ON MINNESOTA WATER SYSTEMS: REPORTRussian state-sponsored hackers can steal passwords, two-factor authentication tokens and up to 90 days of email when users view malicious messages in unpatched Zimbra accounts.(Kurt "CyberGuy" Knutsson)CyberGuy Live: Missed "Sick of Spam?" Get the replay and checklistOur free CyberGuy Live class, "Sick of Spam?" has ended, but you can still watch the full replay and download our spam-stopping checklist.
Kurt "CyberGuy" Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages.You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.Get the free replay and checklist now at CyberGuyLive.com.Laundry Bear, which Microsoft tracks as Void Blizzard, exploits a security flaw known as CVE-2025-66376.
The cross-site scripting vulnerability affects the Classic user interface in certain versions of the Zimbra Collaboration Suite.Zimbra is an email and collaboration platform us...