Tag: Zimbra Zero-Day

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
News

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A then-unknown vulnerability in Zimbra's webmail software allowed a Russian state-sponsored espionage operation to read Western mailboxes for months. The last ninety days' worth of emails, the organization's whole email directory, the browser password, and the codes stored for two-factor recovery are all targeted by the payload. It only took opening the message to get it going. In addition to research from Palo Alto Networks' Unit 42 and Proofpoint, the NSA, CISA, and partner agencies released a joint advisory on the effort on Thursday. The method is described in the alert as "a view-based exploit that only requires a user to view a malicious email" in a client that is susceptible. It claims that since at least July 2025, the actors have been using Zimbra to target and compromise...