CyberSecurityBoardThreat Intel · CVEs · Products
Malware

ZimReaper: Malicious JavaScript Payload for Email Harvesting

July 23, 2026

ZimReaper is a malicious JavaScript payload delivered via CVE-2025-66376 in Zimbra's Classic UI. It harvests email communications and other sensitive data from compromised Zimbra mail servers, used by the threat actor Laundry Bear.