cvekit
LIVE
Threat actors

Void Blizzard

crimewareRUvia MISP

2 CVEs attributed

Aliases4

LAUNDRY BEARLaundry BearTA488UAC-0190
Void Blizzard’s cyberespionage operations tend to be highly targeted at specific organizations of interest to the Russian government, including in government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors primarily in Europe and North America. The threat actor uses stolen credentials—which are likely procured from commodity infostealer ecosystems—and collects a high volume of email and files from compromised organizations.

Attributed CVEs2

CVEDescriptionSeverityEPSSFlagsModified
CVE-2026-42897

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

MEDIUM6.1
71%p99
KEVPoC
2026-08-10
CVE-2025-66376

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

MEDIUM6.1
19%p97
KEV
2026-06-17