HIGH: Russian Spies Turned a Medium-Severity Zimbra Bug Into a 2FA Heist
Russian state-supported actor LAUNDRY BEAR (Void Blizzard) exploited a zero-click Zimbra Collaboration XSS flaw, CVE-2025-66376, as a zero-day for months, stealing 90 days of email, Global Address Lists, saved passwords, and 2FA recovery codes from NATO and Ukrainian targets before minting rogue application passwords for persistent MFA-bypassing access. Patched in November 2025 and now on the CISA KEV list.