I think my comment about the rules update might have been slightly misleading, we only supply the rules with each upgrade and there's no automatic update withing Zimbra.
There used to be a script called rules_du_jour but that seems to have died, you can run saupdate. Have a look at this thread for some details:
Rules_Du_Jour
Did you check the spam/ham accounts were set correctly?