Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

23 July 2026 at 13:33

A Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from more than a dozen other countries warned in a joint cybersecurity advisory Thursday.

Laundry Bear’s most recent espionage campaign involves the exploitation of a zero-day vulnerability in Zimbra Collaboration Suite that wasn’t patched until November 2025, five months after attacks were well underway, officials said. 

The exploit just requires a view — no clicks — and allows attackers to steal the previous 90 days’ worth of email, the account’s password, search history, the victim organization’s email directory, two-factor authentication tokens and other newly created passwords.

“The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing,” officials wrote in the advisory. 

“Additionally, extensive Ukrainian targeting, prior to use against U.S. and other NATO allies, outlines an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.”

The state-sponsored espionage group, also known as Void Blizzard, has compromised governments and organizations in the defense, education, energy, law enforcement, media, finance, transportation and technology sectors. 

Laundry Bear’s year-long campaign involving the exploitation of CVE-2025-66376 showcases more technical capabilities, including a custom JavaScript payload it delivers to targeted victims via phishing emails. The threat group could also likely adapt the novel data exfiltration and aggregation capability, dubbed “beehive,” to exploit other vulnerabilities, officials warned.

The defect’s medium-severity rating of 6.1 underscores the challenge defenders regularly confront in prioritizing patching schedules based on measure of severity alone.

The Russian state-supported group, which has been active since at least 2024, is still actively exploiting Zimbra Collaboration Suite instances that remain unpatched, officials said.

Authorities shared Thursday indicators of compromise, mitigation steps and urged organizations to update their vulnerable software.

“This campaign’s targeted victimology and limited exploitation capabilities likely indicate this group manually identifies and targets the victim organizations” by identifying organizations with public-facing infrastructure, officials wrote in the advisory.

Once a target is identified, Laundry Bear also likely compiles email addresses for users to target with the exploit via phishing emails. Officials did not identify specific victims or describe the volume of organizations already compromised.

The joint cybersecurity advisory was issued by the United States, Australia, Canada, New Zealand, the United Kingdom, Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, the Netherlands, Poland, Spain and Sweden.

The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberScoop.

Spain arrests suspected hacker linked to Russian hacktivist campaign

7 July 2026 at 17:57

Authorities arrested an alleged member of Cyber Army of Russia Reborn, a pro-Russian hacktivist group accused of committing multiple attacks against critical infrastructure providers in the United States and Europe. 

Spain’s national police announced the arrest Monday but said it occurred back in March. Officials did not name the man who was detained at his home in Palencia following an investigation triggered by a tip from the FBI in August 2025.

FBI agents in the Los Angeles field office coordinated with Spanish officials to capture the alleged cybercriminal, the agency’s cyber division said in a LinkedIn post Monday. The FBI said the arrest was part of Operation Riptide, an ongoing global campaign targeting cybercriminals and the infrastructure and financial networks they use to commit fraud.

“Together, we will continue to impose costs on cybercriminals wherever they operate,” the FBI said.

Spanish officials said the arrested man provided logistical support to a Ukrainian hacker linked to Cyber Army of Russia Reborn, also known as Z-Pentest, facilitating the Ukrainian’s escape to Russia via Poland and Belarus. 

The arrested man also “participated in actions attributed to the pro-Russian hacktivist group NoName057(16), whose operations were later claimed in specialized portals related to geopolitics, with the aim of spreading pro-Russian and anti-Western narratives,” Spanish authorities said.

Police investigators searched the suspect’s home and seized computers and cryptocurrency storage devices, later freezing a cryptocurrency wallet he allegedly used to receive payment for his alleged crimes. 

Officials said the nearly year-long investigation recently concluded but did not announce specific charges, other than accusing him of collaborating with a terrorist organization, glorifying terrorism and damaging computers.

Authorities have been targeting Cyber Army of Russia Reborn and its alleged members for years. The Russian state-sponsored group has been active since 2022, officials said. 

The Treasury Department sanctioned the pro-Russian hacktivist group’s alleged leader and primary hacker, Yuliya Vladimirovna Pankratova and Denis Olegovich Degtyarenko, in July 2024.

In December 2025, the Justice Department indicted Ukrainian national Victoria Eduardovna Dubranova, accusing her of participating in attacks against critical infrastructure and other victims in support of Russia’s geopolitical interests as part of Cyber Army of Russia Reborn and NoName057(16). Dubranova was extradited to the United States last year and pleaded guilty in two federal cases brought against her. 

The State Department since late 2025 has been offering potential rewards for up to $2 million for information on individuals associated with Cyber Army of Russia Reborn and up to $10 million for information on individuals associated with NoName. NoName057(16), also known as NoName, was established by Russian President Vladimir Putin in October 2018, according to the Justice Department.

Multiple federal agencies and international partners issued a joint cybersecurity advisory in December 2025 about threats posed by pro-Russian hacktivist groups, including Cyber Army of Russia Reborn and NoName.

The post Spain arrests suspected hacker linked to Russian hacktivist campaign appeared first on CyberScoop.

❌
❌