Russian Hackers Used a 'Half-Click' Email Exploit to Target NATO Nations

Close identity gaps before they are exploited

Enforce strong authentication and eliminate weak password practices with a unified identity protection approach. With ADSelfService Plus, reduce risk while keeping access seamless for users.

๐Ÿ”Ž Cyber Watch ๐Ÿ”Ž

Russian Hackers Used a 'Half-Click' Email Exploit to Target NATO Nations

The United States and more than a dozen allied countries have attributed a new cyber espionage campaign to the Russian state-backed hacking group Laundry Bear. The attackers exploited a now-patched vulnerability in the Zimbra email platform that allowed them to steal emails after a user simply opened a malicious message. Unlike traditional phishing attacks, victims did not need to click a link or open an attachment. Cybersecurity firm Proofpoint described the technique as a "half-click exploit" because no social engineering was required.

Authorities said the campaign first targeted organizations in Ukraine before expanding to the United States and several NATO member states. The joint advisory highlights how nation-state attackers continue to refine zero-click and low-interaction attack methods that can bypass user awareness training and traditional phishing defenses.

Key takeaways

  • Russian-linked hackers used a Zimbra vulnerability that required users only to open an email.

  • The campaign reportedly began in Ukraine before expanding to NATO countries.

  • Organizations should prioritize rapid patching of internet-facing applications, as modern attacks increasingly rely on software flaws rather than user mistakes.

๐ŸŽ™๏ธ Tech Briefing Onโ€‘Air ๐ŸŽ™๏ธ

Securing Legacy Software

Speaking at RSAC 2026, Alex Mosher, President and CRO of Armis, argued that organizations need to move beyond the traditional "fortress" approach to cybersecurity. Instead of relying mainly on perimeter defenses, security teams should focus on gaining complete visibility across every connected asset, including legacy systems that often remain unmanaged and vulnerable. He also highlighted how AI can help security teams manage growing vendor sprawl, identify risks faster, and better align cybersecurity investments with business goals.

Takeaways

  • Complete asset visibility is becoming the foundation of modern cyber defense.

  • Legacy software and unmanaged devices remain attractive targets for attackers.

  • AI can help security teams prioritize risks, reduce operational complexity, and improve cyber resilience.

๐Ÿค Partner Intel ๐Ÿค

Reduce Password Resets Without Sacrificing Security

Password resets remain one of the biggest drivers of help desk tickets. ManageEngine ADSelfService Plus helps organizations reduce that burden by allowing users to securely reset passwords, unlock accounts, and update credentials without IT assistance. The platform also supports MFA, password policy enforcement, adaptive authentication, and single sign-on, helping organizations strengthen identity security while improving the employee experience.

Why it stands out

  • Self-service password reset and account unlock

  • Multi-factor authentication for Windows, VPNs, cloud apps, and endpoints

  • Password synchronization across multiple enterprise applications

  • Adaptive authentication based on risk factors

  • Reduces help desk workload while improving identity security.

๐Ÿค– AI Runtime ๐Ÿค–

Should Governments Have an AI Emergency Stop Button?

US lawmakers are proposing the AI Kill Switch Act, which would require advanced AI systems to include mechanisms that allow authorities to slow down or shut down models during catastrophic incidents. The proposal follows growing concern about autonomous AI behaviour and high-profile security testing involving advanced models. Supporters say it protects public safety, while critics warn it could slow innovation and create new governance challenges.

๐Ÿ“Š By the Numbers ๐Ÿ“Š

๐Ÿ—ณ๏ธ Your Monday Take ๐Ÿ—ณ๏ธ

Cast your vote on our weekly poll.

Which security control gives organizations the biggest false sense of security?

Login or Subscribe to participate in polls.

๐Ÿ“ฉ Weโ€™ll share the results in the Friday issue.

Advertise with Comparitech
Does your business offer services or products in cybersecurity? Get your product seen by IT leaders and professionals.

Advertise with us โ†’

Until Wednesdayโ€™s edition - Letโ€™s keep that zero-day count at zero!