ADVERTISEMENT

Russian spies feast on NATO member data through flaw many haven't patched

Hackers quietly tested the zero-click tactic in Ukraine before targeting NATO member organizations, CISA says.

Russian hackers, cyberattack

Image by Cybernews.

Stefanie Schappert
Stefanie Schappert Senior Journalist
July 23, 2026 Updated: July 24, 2026 2 min read
Key takeaways:
CISA and international partners detail the Russian Laundry Bear campaign targeting Zimbra users.
prompt injection attack
Hackers can compromise vulnerable Zimbra email accounts without users clicking links or attachments. Image by Cybernews.

Laundry Bear turns from Ukraine to the West

Russia, hackers, cybercrime, Ukraine
The zero-click campaign allows Russian spies to harvest emails and maintain persistent access to compromised accounts. Image by Hlib Shabashnyi | Shutterstock
ADVERTISEMENT
“Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques – including password spraying, phishing, and pass-the-cookie – allowing the group to successfully run high-volume operations,”
CISA states.

Zero-click attack leaves little for victims to do

Russian hackers, cyberattack
Laundry Bear first tested the campaign in Ukraine before targeting organizations across NATO member countries. Image by Cybernews.
“The exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR,”
the advisory warns.

Unpatched servers remain at risk

Has your password leaked?

Enter your password to check if it has leaked. Having a leaked password creates the risk of identity theft, financial damages, and worse!
35,607,543,468
Exposed Passwords
Ad
Protect your personal information from cybercriminals and get 50% off the top-rated password manager
link_title link_title
Stefanie Schappert
Senior Journalist
ADVERTISEMENT