On July 23, the NSA, CISA, FBI, and partners from thirteen allied nations released a joint advisory detailing how the Russian state-supported group known as Laundry Bear, also tracked as Void Blizzard, spent months inside the mail systems of Western government and commercial organizations. The headline detail is the zero-click exploit. The lesson that should outlast the headline is what the group chose to steal: not just five months of email, but the passwords, 2FA tokens, and organizational directories that turn one compromise into the next five.
What happened?
Beginning in July 2025, Laundry Bear used a custom tool called Ulej to exploit CVE-2025-66376, a flaw in Zimbra Collaboration Suite. The exploit was zero-click: it triggered automatically when a user viewed a malicious email. No attachment opened, no link followed, no credential phished. The preview pane was the attack surface.
Zimbra patched the flaw in November 2025, five months after exploitation began. The advisory, AA26-204A, arrived in July 2026, and it warns the group is still working through servers that never applied the patch. Sixteen nations co-sealed the document, a signal of how widely the campaign reached across government, defense, energy, finance, transportation, and technology targets.
What did they actually take?
According to the advisory, the exfiltration went well beyond reading mail:
- The previous 90 days of email messages
- Account passwords, including newly created ones
- Two-factor authentication tokens
- The organization's complete email directory
- User search history
Read that list as an adversary would. The messages are intelligence with a shelf life. The passwords, 2FA tokens, and directories are capital: reusable keys to accounts, VPNs, and cloud services, plus a validated org chart of exactly who to impersonate next. The mailbox was the entry point. The identity material was the objective.
Why did five months pass unnoticed?
Because nothing about the activity looked wrong. An adversary authenticating with a valid stolen password and a valid stolen 2FA token is indistinguishable from the employee those credentials belong to. There is no malware signature for a correct login. More than 40% of reported attacks involve stolen PKI credentials, and campaigns like this one show why the pattern persists: static secrets, once harvested, keep working until someone happens to notice.
It is worth sitting with the severity score, too. CVE-2025-66376 carries a CVSS rating of 6.1, a medium. Vulnerability scores measure the mechanics of a bug. They say nothing about the blast radius of the long-lived secrets sitting behind it. A medium flaw in front of static credentials produced a five-month, sixteen-nation incident.
The question the patch doesn't answer
Patching Zimbra closes the door Laundry Bear came through. It does nothing about the copies they left with. Every password and 2FA token harvested before the patch remains an open question: rotated or not, discovered or not, reused where, by whom. Incident response after credential theft is an inventory problem with no reliable inventory.
This is the gap Zero Trust was named for. NIST SP 800-207 and the federal Zero Trust mandates all converge on the same requirement: no implicit trust, no standing privilege, every session verified on its own terms. Measured against that bar, a password that stays valid for months and a 2FA token that can be exfiltrated and replayed are architectural debts, not user failures.
Making stolen secrets worthless
AKMSecure approaches the problem from the other end: assume harvesting will happen, and make the harvest worthless. AKM replaces static-credential trust with autonomously refreshed symmetric keys. Every session is independently verified, keys refresh with each session, and no persistent credential exists to be exfiltrated from a mail store, a memory dump, or a preview pane. A key that expired with its session has no value on any adversary's shelf, and there is no five-month window because there is nothing that stays valid for five months.
The immediate guidance stands: patch Zimbra, hunt the advisory's IOCs, reset what may have been exposed. The longer-term question for every federal and defense organization reading AA26-204A is simpler. The adversary's business model depends on secrets that keep working after they are stolen. Stop issuing those, and the model breaks.
About AKMSecure
AKMSecure delivers a patented Autonomous Key Management™ protocol built to replace outdated PKI approaches with a dynamic, quantum-secure, air-gapped-capable architecture. Instead of relying on persistent credentials that can be stolen, reused, or abused, AKM enables independently verified sessions with no standing privileges left behind. The result is a model that better aligns with Zero Trust principles, reduces certificate-based risk, and supports resilient operations across enterprise IT, OT and Tactical Edge environments. Built to NSA-grade security standards and deployable as a lightweight SDK, AKMSecure helps organizations modernize trust at the protocol layer without rebuilding everything around it.

