Fox News Flash top headlines are here. Check out what's clicking on FoxNews.com.
Opening an unexpected email can feel relatively harmless when you avoid its links and attachments. However, a Russian hacking campaign has turned that familiar safety advice on its head.
CISA says the Russian state-sponsored group Laundry Bear can compromise certain email accounts when someone simply opens or previews a malicious message. The attack targets organizations running unpatched versions of the Zimbra Collaboration Suite.
Once the email appears, hidden code can collect passwords, authentication data and as much as 90 days of messages. You may never see a warning or realize that anything happened.
The Cybersecurity and Infrastructure Security Agency issued the warning with the National Security Agency, FBI and cyber authorities from several allied countries. The agencies say the group has successfully targeted more than 10 Western organizations since July 2025.
INVESTIGATORS BELIEVE IRANIAN HACKERS ARE LIKELY BEHIND CYBERATTACK ON MINNESOTA WATER SYSTEMS: REPORT
Russian state-sponsored hackers can steal passwords, two-factor authentication tokens and up to 90 days of email when users view malicious messages in unpatched Zimbra accounts. (Kurt "CyberGuy" Knutsson)
CyberGuy Live: Missed "Sick of Spam?" Get the replay and checklist
Our free CyberGuy Live class, "Sick of Spam?" has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt "CyberGuy" Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.
Get the free replay and checklist now at CyberGuyLive.com.
Laundry Bear, which Microsoft tracks as Void Blizzard, exploits a security flaw known as CVE-2025-66376. The cross-site scripting vulnerability affects the Classic user interface in certain versions of the Zimbra Collaboration Suite.
Zimbra is an email and collaboration platform used by some governments, schools, businesses and other organizations as an alternative to services such as Microsoft Exchange or Google Workspace. Attackers can place malicious JavaScript inside a specially crafted HTML email. That code runs automatically when a vulnerable Zimbra webmail client displays the message.
The person reading the email does not need to open an attachment. The attack also avoids the usual request to enter a password on an obvious phishing page. However, the email still needs to appear on the screen. CISA describes the technique as a zero-click exploit. Proofpoint calls it a "half-click" attack because someone must open the email or allow it to appear in a preview pane. Either description leads to the same concern. A message can look harmless while code hidden inside it quietly attacks the email account.
Laundry Bear reportedly used the flaw as a zero-day before Zimbra released a patch in November 2025. A zero-day attack exploits a security weakness before the software maker provides a fix. CISA later added the vulnerability to its list of flaws that hackers actively exploit.
The available patch closes the known security hole. Yet Laundry Bear continues to target organizations that have not installed the update. That makes delayed patching especially dangerous. An organization may have strong passwords and trained employees, but an exposed email server can still give attackers another way inside.