Key Findings Russian state-sponsored group Laundry Bear (also known as Void Blizzard) exploited a zero-day vulnerability in Zimbra Collaboration Suite for five months before patch in November 2025 CVE-2025-66376 requires only viewing a malicious email to trigger exploit—no user interaction needed beyond opening the message Single exploit steals 90 days of email history, account passwords, 2FA tokens, organization email directory, and search history Targets span government, de