home.social

#zimbra — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zimbra, aggregated by home.social.

fetched live
  1. Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    Indicators extracted from public reporting. Source: media.defense.gov/2026/Jul/22/

    Pulse ID: 6a79ace8ce2eec075b55ddb0
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:50:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL

  2. Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    Indicators extracted from public reporting. Source: media.defense.gov/2026/Jul/22/

    Pulse ID: 6a79ace8ce2eec075b55ddb0
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:50:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL

  3. Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!

    Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
    Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
    Payload zdekodowany przez Proofpoint
    Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
    Rosjanie próbowali wykradać:

    wiadomości z ostatnich 90 dni,
    książkę adresową organizacji,
    hasła podpowiadane przez przeglądarkę,
    awaryjne kody 2FA i token CSRF,

    Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
    Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]

    #AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra

    niebezpiecznik.pl/post/rosjani

  4. Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!

    Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
    Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
    Payload zdekodowany przez Proofpoint
    Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
    Rosjanie próbowali wykradać:

    wiadomości z ostatnich 90 dni,
    książkę adresową organizacji,
    hasła podpowiadane przez przeglądarkę,
    awaryjne kody 2FA i token CSRF,

    Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
    Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]

    #AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra

    niebezpiecznik.pl/post/rosjani

  5. 📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

    Listen/Read: hackread.com/russian-hackers-z

    #CyberSecurity #Zimbra #0day #Vulnerability #Russia #TA488

  6. 📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

    Listen/Read: hackread.com/russian-hackers-z

    #CyberSecurity #Zimbra #0day #Vulnerability #Russia #TA488

  7. CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

    Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

    Reward: You've received a hollow Authenticator Token — pre-drained.

    #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

  8. CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

    Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

    Reward: You've received a hollow Authenticator Token — pre-drained.

    #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

  9. Email Theft Campaign Exploits Zimbra Zero-Click Flaw

    Pulse ID: 6a630d8195ebe8af82f8ade3
    Pulse Link: otx.alienvault.com/pulse/6a630
    Pulse Author: cryptocti
    Created: 2026-07-24 07:00:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti

  10. Email Theft Campaign Exploits Zimbra Zero-Click Flaw

    Pulse ID: 6a630d8195ebe8af82f8ade3
    Pulse Link: otx.alienvault.com/pulse/6a630
    Pulse Author: cryptocti
    Created: 2026-07-24 07:00:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti

  11. Zimbra Mailservers Targeted with Half-Click Exploits

    Pulse ID: 6a62e8b79c1d4745bf2b24b5
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:23:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111

  12. Zimbra Mailservers Targeted with Half-Click Exploits

    Pulse ID: 6a62e8b79c1d4745bf2b24b5
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:23:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111

  13. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  14. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  15. Zimbra Mailservers Targeted with Half-Click Exploits

    Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.

    Pulse ID: 6a6241a85c158acad5feb72c
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault

  16. Zimbra Mailservers Targeted with Half-Click Exploits

    Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.

    Pulse ID: 6a6241a85c158acad5feb72c
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault

  17. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

    Pulse ID: 6a6241a95227e5bddd350d13
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault

  18. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

    Pulse ID: 6a6241a95227e5bddd350d13
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault

  19. Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. radar.offseq.com/threat/zimbra #OffSeq #Zimbra #InfoSec #Vuln

  20. Zimbra: 47 CVEs, 8 exploited in CISA KEV, 100% unpatched. Trust Score: D. Email security risk—patch now. #Zimbra #cybersecurity #infosec

    valtersit.com/vendors/zimbra/

  21. Zimbra: 47 CVEs, 8 exploited in CISA KEV, 100% unpatched. Trust Score: D. Email security risk—patch now. #Zimbra #cybersecurity #infosec

    valtersit.com/vendors/zimbra/

  22. Zimbra Collaboration Suite Classic Web Client <10.1.19 has a CRITICAL stored XSS vulnerability — malicious code can execute when crafted emails are opened, risking mailbox and session compromise. Patch to 10.1.19 now. radar.offseq.com/threat/zimbra #OffSeq #Zimbra #AppSec #XSS

  23. Zimbra: 47 CVEs, 100% unpatched, 8 CISA KEV exploited. Avg CVSS 6.03, max 10. Trust Score: D. Email collaboration platform under active attack. Patch or migrate now. #Zimbra #infosec #cybersecurity

    valtersit.com/vendors/zimbra/

  24. Zimbra: 47 CVEs, 100% unpatched, 8 CISA KEV exploited. Avg CVSS 6.03, max 10. Trust Score: D. Email collaboration platform under active attack. Patch or migrate now. #Zimbra #infosec #cybersecurity

    valtersit.com/vendors/zimbra/

  25. Zimbra Servers Targeted in Ongoing XSS Attacks

    Beware of sneaky phishing emails that can hijack your Zimbra server with just a glance - no clicks or downloads required. A single malicious email can trigger a cross-site scripting attack, thanks to a recently patched vulnerability, CVE-2025-48700.

    osintsights.com/zimbra-servers

    #CrosssiteScripting #Zimbra #Cve202548700 #XssAttacks #EmailExploits