New Warnings that Russian Operatives Are Targeting the Emails of US Nuclear Scientists and Defense Contractors
U.S. and allied agencies said the group used a patched Zimbra flaw that let hackers steal emails after a user opened a message.
- On Thursday, the United States and more than a dozen allied nations attributed a widespread Zimbra email theft campaign to Russian hackers, identifying the group as Laundry Bear, also known as Void Blizzard.
- According to 27 international agencies, these attacks have been ongoing since July 2025, using a Zimbra vulnerability described as a "half-click exploit" that triggers data theft the moment a victim views an email.
- The campaign targets a cross-site scripting vulnerability, CVE-2025-66376, to inject malicious JavaScript into Western organizations, while attackers exfiltrate data using a custom framework named "Flowerbed" that shows signs of artificial intelligence development.
- British Security Minister Dan Jarvis stated, "It's particularly concerning that these thugs tested their methods on victims in Ukraine, before targeting members of NATO," as an indictment links the group to Russian company Yutek-NN.
- Agencies recommend minimizing webmail use until systems are patched, while Yutek-NN deputy director Denis Obrezko faces hacking-related charges in Boston following his arrest in Thailand last year.
50 Articles
50 Articles
Russian State-Backed Hackers Target US Defense and Nuclear Organizations
Russian hackers spent the past year targeting the emails of US nuclear scientists, defense contractors, and government employees, according to researchers and Western intelligence agencies, on July 24. The warning came in a joint advisory from security and intelligence agencies in the US and more than a dozen allied countries, CNN reported on the same day. The US cybersecurity firm Proofpoint documented part of the same activity in its own inves…
Édouard Philippe, presidential candidate, was the target of a disinformation operation orchestrated by a pro-Russian network. This is the first time that a 2027 presidential contender has been targeted by such a campaign, on the basis of fear of foreign interference.
The activities have also targeted Finland.
Russia has increased cyber espionage as its traditional human intelligence capabilities in the West have been weakened by deportations and sanctions
New Russian Cyber Campaign Lets Hackers Steal Emails exploiting Zimbra Zero-Day Flaw, Warns FBI
FBI and international cyber agencies warned of a Russian-backed phishing campaign exploiting Zimbra email software to steal sensitive data from governments and businesses.
Russian hackers targeting US nuclear scientists and defense contractors, new advisory says
A group of Russian hackers has spent the last year targeting nuclear scientists, defense contractors, and government employees in a cyber-espionage campaign
Coverage Details
Bias Distribution
- 78% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium



















