Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
CISA Warns Russian Hackers Can Hijack Email Just by You Opening It, No Clicks Needed

Federal cybersecurity officials say a Russian state-sponsored hacking group has found a way into email accounts that requires almost nothing from the victim. Just previewing or opening a malicious message can be enough.
The Cybersecurity and Infrastructure Security Agency, working with the National Security Agency, the FBI and cyber authorities from allied countries, issued a joint advisory identifying the group as Laundry Bear. Microsoft tracks the same group under the name Void Blizzard. According to the advisory, the group has successfully targeted more than 10 Western organizations since July 2025.
The attack exploits a specific vulnerability, CVE-2025-66376, a cross-site scripting flaw in the Classic user interface of certain unpatched versions of Zimbra Collaboration Suite. Zimbra is an email and collaboration platform used by some government agencies, schools and businesses as an alternative to Microsoft Exchange or Google Workspace.
Here's how it works. Attackers embed malicious JavaScript inside a specially crafted HTML email. When a vulnerable Zimbra webmail client displays that message, the code runs automatically. There's no attachment to open, no obvious phishing page asking for a password. The victim just has to let the email render on screen.
Once triggered, the hidden code can harvest passwords, two-factor authentication data and up to 90 days of email history, according to the advisory. Victims often have no idea it happened. No warning pops up. No suspicious link gets clicked.
CISA calls this a zero-click exploit. The security firm Proofpoint describes it as a "half-click" attack, since a user still has to open the email or have it appear in a preview pane for the code to fire. Whether you call it zero-click or half-click, the practical effect is the same: standard advice to avoid clicking suspicious links doesn't fully protect you here.
This is a meaningful shift from typical phishing campaigns, which usually depend on tricking someone into clicking a bad link or downloading an infected file. Security awareness training for years has centered on exactly that behavior. An exploit that fires just from a message being displayed sidesteps that entire defense model.
The advisory identifies a specific vulnerability, a specific vendor, a specific attacker group, and a specific number of confirmed victims: more than 10 organizations since July 2025. What isn't public yet, at least in this advisory, is a full list of which organizations were breached, how much data was actually exfiltrated in each case, or whether any classified or highly sensitive government systems were among the targets.
The fix, according to the joint advisory, is straightforward: patch affected Zimbra Collaboration Suite installations. Organizations running outdated versions of Zimbra's Classic interface are the ones at risk. Once patched, the specific cross-site scripting flaw is closed.
That raises an obvious question for any organization still running unpatched Zimbra systems: why hasn't it happened yet? Software vendors routinely issue patches for known vulnerabilities, and CVE-2025-66376 has a name and a number precisely because it's been identified and, presumably, addressed in current releases. The gap between a patch being available and organizations actually installing it is where campaigns like this one thrive.
This isn't the only nation-state cyber threat active against American infrastructure right now. Investigators have also said they believe Iranian hackers were likely behind a separate cyberattack on Minnesota water systems, underscoring that state-linked hacking campaigns against Western targets are running on multiple fronts simultaneously, not just from Russia.\
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.