Russian hackers can steal government emails without victims clicking a link, cyber agencies warn
da-kuk/Getty Images
ByDavid DiMolfetta,
Cybersecurity Reporter, Nextgov/FCW
July 23, 2026 01:13 PM ET
The Russia-linked Laundry Bear group has compromised more than 10 Western organizations through malicious emails that can trigger an exploit when they are viewed or previewed.
Russian state-backed hackers have exploited a vulnerability in widely used email software to steal messages, passwords and authentication data from Western government agencies and other organizations, U.S. and allied cyber-intelligence authorities said Thursday.
The campaign is notable because it does not require victims to click a malicious link or download an attachment. The exploit can instead activate when someone simply opens or previews an email in an unpatched version of the Zimbra Collaboration Suite — a popular alternative to major collaborative messaging platforms like Microsoft Exchange or Google Workspace — according to a joint advisory issued by the Cybersecurity and Infrastructure Security Agency, National Security...
Copyright of this story solely belongs to nextgov.com. To see the full text click HERE