🔥 この記事の詳細
2026-07-23 更新
B
今週中

ロシア政府が支援する脅威グループ「Laundry Bear」が、Zimbra Collaboration Suiteのゼロデイ脆弱性を悪用して西側諸国の政府や企…

脆弱性🌐 英語ソース📰 3記事🌐 2 countries
🇺🇸 US (2) · 🇹🇼 Taiwan
🖥️ 製品Zimbra
📅 2026-07-23📰 cyberscoop
📌 一言でいうと
ロシア政府が支援する脅威グループ「Laundry Bear」が、Zimbra Collaboration Suiteのゼロデイ脆弱性を悪用して西側諸国の政府や企業から機密データを窃取しています。この攻撃は2025年7月から開始されており、ユーザーがメールを表示するだけで、過去90日分のメール、パスワード、2要素認証トークンなどが盗まれる可能性があります。脆弱性は2025年11月に修正されましたが、攻撃はそれより数ヶ月前から行われていました。
🔍該当判定
  • メールサーバーに「Zimbra Collaboration Suite」を利用している
  • LinuxベースのグループウェアとしてZimbraを運用している
  • Zimbraのアップデートを2025年11月以降に実施していない
上記いずれにも該当しない → 静観でOK
該当時の対応
Zimbra Collaboration Suiteを最新バージョンにアップデートし、脆弱性が修正されているか確認してください。また、不審なメールの受信や、アカウントの異常なログイン履歴がないか監視を強化してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Zimbra Collaboration Suite ゼロデイ脆弱性悪用について

お疲れさまです。Zimbra Collaboration Suiteにおける深刻な脆弱性の悪用に関する情報共有です。

■ 概要
ロシアのAPTグループ「Laundry Bear」が、Zimbraのゼロデイ脆弱性を悪用して機密情報を窃取しています。攻撃者はメールを閲覧させるだけで、過去90日分のメール、パスワード、2FAトークンなどを取得可能です。

■ 影響範囲
- Zimbra Collaboration Suite (2025年11月のパッチ適用前のバージョン)

■ 対応手順
1. Zimbra Collaboration Suiteを最新バージョンへアップデートし、2025年11月リリースの修正を適用してください。
2. 過去に不審なメールが配信されていなかったか、および特権アカウントのログイン履歴を確認してください。

■ 参考情報
- 米国および同盟国による共同サイバーセキュリティアドバイザリ

対応優先度: 高
対応期限: 至急
Subject: [Security Advisory] Exploitation of Zimbra Collaboration Suite Zero-Day

Dear IT/Security Team,

We are sharing information regarding a critical vulnerability exploitation in Zimbra Collaboration Suite.

■ Overview
The Russian state-sponsored group "Laundry Bear" has been exploiting a zero-day vulnerability to steal sensitive data. The exploit requires no user interaction beyond viewing a message and allows the theft of 90 days of emails, passwords, and 2FA tokens.

■ Scope
- Zimbra Collaboration Suite (versions prior to the November 2025 patch)

■ Action Plan
1. Immediately update Zimbra Collaboration Suite to the latest version to ensure the November 2025 patch is applied.
2. Audit account logs for unauthorized access and review email logs for suspicious activity.

■ Reference
- Joint Cybersecurity Advisory from U.S. and international authorities

Priority: High
Deadline: Immediate