Russian state-sponsored cyber actors, tracked as LAUNDRY BEAR, are conducting a sophisticated phishing campaign targeting users of the Zimbra Collaboration Suite (ZCS). The campaign exploits a zero-day vulnerability (CVE-2025-66376) to exfiltrate email data, organizational directories, and other sensitive information from Western government and commercial organizations. This activity, which began in July 2025, demonstrates an increasing technical capability by the threat group, primarily focused on espionage.