A Threat That Needed Almost No Action From Victims
Government security agencies have issued a warning about a Russian state-backed hacking group that spent months quietly reading the email of organizations in the United States and Ukraine. The group, tracked under names including Laundry Bear and Void Blizzard, found a way into Zimbra Collaboration email servers using a flaw that required almost nothing from the person being targeted.
Most phishing attacks need a victim to click a link or open an attachment. This one did not. Investigators say the malicious email only needed to be opened or even previewed in the inbox for the attack to begin. Security researchers call this a half-click or zero-click attack, because the usual warning signs, like a suspicious link or a request to enable content, simply were not there.
What The Hackers Were After
Once the booby-trapped message ran on a vulnerable Zimbra server, it quietly pulled out a range of sensitive information, including:
- Emails from the last 90 days
- The organization's full email directory and contact list
- Passwords stored in the browser
- Backup codes used for two-factor authentication recovery
That last item stands out. Two-factor authentication is one of the strongest everyday defenses people have against account takeover. By grabbing recovery codes along with passwords, the attackers gave themselves a way to get back into accounts even if a victim later changed their password or reset their login credentials.
Agencies involved in the warning, including CISA and the NSA, say the goal appears to be long-term espionage rather than quick financial theft. The targets skewed toward government bodies, defense-related organizations, and groups tied to Ukraine, which lines up with past activity linked to Russian state-backed hacking operations.
The Flaw Has Already Been Fixed
Zimbra has released a patch for the vulnerability, and organizations running Zimbra Collaboration servers are being told to update immediately if they have not already. The flaw was a zero-day, meaning it was actively being used by attackers before a fix was available, which is why security agencies moved quickly to publish details once a patch existed.
The danger did not end with the patch, though. Anyone whose account was exposed before the update may still have had emails, contacts, saved passwords, or two-factor recovery codes stolen during the window the flaw was active. That means organizations that used Zimbra need to check their systems for signs of past compromise, not just apply the patch and move on.
A Separate Warning About Redis
In an unrelated development, the team behind the popular Redis database software also pushed out seven security updates on the same day. Researchers had found serious flaws in several versions of Redis that could allow an attacker who already has some access to a system to run their own code on it, a type of attack known as remote code execution.
Notably, some of these flaws were reportedly discovered with help from AI-based research tools rather than a traditional human-led search, an approach that is becoming more common in security research. Redis has released fixed versions, and organizations that rely on Redis for data storage or caching should apply the updates as soon as practical.
While Redis is mostly used behind the scenes by businesses and app developers rather than directly by everyday consumers, it powers a huge number of websites and online services people use daily. Keeping it patched matters for the overall safety of the internet, even if most readers will never interact with it directly.
What You Should Do
- If your organization uses Zimbra Collaboration, confirm the latest security patch has been installed right away.
- If you or your workplace used Zimbra webmail recently, change your email password and any passwords that were saved in your browser.
- Reset your two-factor authentication setup and generate new backup or recovery codes, since old ones may have been stolen.
- Be cautious with unexpected emails even if you never click a link, since simply opening or previewing a message was enough in this case.
- If you manage business software like Redis, check with your IT team to confirm recent security updates have been applied.