🚨 ACTIVE EXPLOITATION
- Russian Laundry Bear exploits Zimbra zero-click flaw to steal emails — BleepingComputer
Russian group Laundry Bear exploited a zero-click Zimbra flaw to steal emails and credentials.- Targets: Organizations using Zimbra Collaboration Suite, including defense, government, education, energy, law enforcement, media, NGOs, and tech sectors
- Vulnerability: CVE-2025-66376, a zero-click cross-site scripting flaw in Zimbra's Classic UI allowing automatic JavaScript execution on email view
- Attack method: Combines phishing with zero-day exploit to steal last 90 days of emails, passwords, Global Address List, 2FA tokens, and creates application passcodes to bypass MFA
- Data exfiltration: Uses DNS A-record queries for small data and HTTPS uploads for larger payloads to attacker-controlled servers running 'Flowerbed' framework
- Ongoing threat: Exploited for five months before patch in November 2025; Laundry Bear continues targeting unpatched systems
🕵️ RESEARCH & DEEP DIVES
- Hackers abuse Notepad++ plugins to stealthily install LunchPoke malware — BleepingComputer
Hackers use malicious Notepad++ plugins to stealthily install malware via ZIP archives.- Targets organizations in Ukraine using Notepad++ version 8.8.3
- Attack delivers ZIP archive containing legitimate Notepad++, malicious plugin DLL (LunchPoke), and payloads
- Malicious plugin loads via Notepad++ plugin mechanism to establish persistence with scheduled tasks
- Payload includes MatchBoil V2 malware loader and resource exhaustion fallback attack
- Delivery via VBS script disguised as PDF that extracts further archives and launches malware
🔓 CVEs & KEV
- 19 CVEs reported, worst scoring 9.9 in severity.