CyberDefenseMagazine

New CISA/NSA Advisory Spotlights Russian Attacks on Zimbra Webmail


Overview of the Advisory

On July 23, 2026, CISA, the NSA, the FBI, and their international partners issued a joint cybersecurity advisory alerting organizations to ongoing Russian state-sponsored activity. The alert details an active espionage campaign run by the threat group commonly tracked as LAUNDRY BEAR. Active since at least July 2025, these state-backed actors have been systematically targeting Western government agencies, defense contractors, law enforcement groups, and commercial organizations relying on the Zimbra Collaboration Suite for webmail.

Exploitation Vector and Mitigations

The alert claims that LAUNDRY BEAR exploits unpatched Zimbra installations using a unique data-exfiltration tool known as Ulej. This campaign uses a zero-click vulnerability instead of conventional phishing techniques that deceive a user into clicking a link or downloading a file. When an operator previews an email on a susceptible web interface, the malicious payload initiates automatically. The script tries to gather contact lists, user credentials, two-factor authentication tokens, and internal emails for up to 90 days after it is launched. Security experts highly advise network administrators to put defensive network measures in place and deploy the most recent Zimbra updates right away.

Author Notes

Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), et al., Joint Cybersecurity Advisory AA26-204A: “Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite”

About the Author

Carmen Estela is a Cybersecurity Research Analyst at Cyber Defense Magazine and a Women in Cybersecurity Award Candidate. She recently graduated with a Master’s of Science degree from the University of Central Florida and holds a Bachelor’s degree in Criminology from the University of Florida with certifications in Data Analytics and AI Fundamentals. She frequently speaks and volunteers at well-known industry gatherings, such as BSides Orlando and BSides Jax, where she offers her perspectives on emerging cyber trends. Carmen is committed to advancing the standards of governance, risk, and compliance within cybersecurity. She has also served as an adult protective investigator, police dispatcher, and legal intern, applying investigative skills across law enforcement, academic, and public service settings. 

Reach her online at [email protected].

 



Source link