#zimbra — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #zimbra, aggregated by home.social.
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Indicators extracted from public reporting. Source: https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
Pulse ID: 6a79ace8ce2eec075b55ddb0
Pulse Link: https://otx.alienvault.com/pulse/6a79ace8ce2eec075b55ddb0
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:50:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Indicators extracted from public reporting. Source: https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
Pulse ID: 6a79ace8ce2eec075b55ddb0
Pulse Link: https://otx.alienvault.com/pulse/6a79ace8ce2eec075b55ddb0
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:50:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Indicators extracted from public reporting. Source: https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
Pulse ID: 6a79ace8ce2eec075b55ddb0
Pulse Link: https://otx.alienvault.com/pulse/6a79ace8ce2eec075b55ddb0
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:50:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Indicators extracted from public reporting. Source: https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
Pulse ID: 6a79ace8ce2eec075b55ddb0
Pulse Link: https://otx.alienvault.com/pulse/6a79ace8ce2eec075b55ddb0
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:50:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL
-
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Indicators extracted from public reporting. Source: https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF
Pulse ID: 6a79ace8ce2eec075b55ddb0
Pulse Link: https://otx.alienvault.com/pulse/6a79ace8ce2eec075b55ddb0
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:50:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL
-
Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!
Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
Payload zdekodowany przez Proofpoint
Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
Rosjanie próbowali wykradać:wiadomości z ostatnich 90 dni,
książkę adresową organizacji,
hasła podpowiadane przez przeglądarkę,
awaryjne kody 2FA i token CSRF,Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]#AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra
-
Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!
Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
Payload zdekodowany przez Proofpoint
Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
Rosjanie próbowali wykradać:wiadomości z ostatnich 90 dni,
książkę adresową organizacji,
hasła podpowiadane przez przeglądarkę,
awaryjne kody 2FA i token CSRF,Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]#AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra
-
Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!
Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
Payload zdekodowany przez Proofpoint
Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
Rosjanie próbowali wykradać:wiadomości z ostatnich 90 dni,
książkę adresową organizacji,
hasła podpowiadane przez przeglądarkę,
awaryjne kody 2FA i token CSRF,Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]#AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra
-
Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!
Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
Payload zdekodowany przez Proofpoint
Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
Rosjanie próbowali wykradać:wiadomości z ostatnich 90 dni,
książkę adresową organizacji,
hasła podpowiadane przez przeglądarkę,
awaryjne kody 2FA i token CSRF,Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]#AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra
-
Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!
Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
Payload zdekodowany przez Proofpoint
Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
Rosjanie próbowali wykradać:wiadomości z ostatnich 90 dni,
książkę adresową organizacji,
hasła podpowiadane przez przeglądarkę,
awaryjne kody 2FA i token CSRF,Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]#AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra
-
Reward: Congratulations! You've received a Loot Box containing your own sent folder, read receipts, and attachments. Non-transferable. Non-refundable. Already transferred.
#Cybersecurity #RussianHackers #Zimbra #EmailSecurity #ZeroDay #NoSocialEngineeringNeeded (3/3)
-
Reward: Congratulations! You've received a Loot Box containing your own sent folder, read receipts, and attachments. Non-transferable. Non-refundable. Already transferred.
#Cybersecurity #RussianHackers #Zimbra #EmailSecurity #ZeroDay #NoSocialEngineeringNeeded (3/3)
-
Russische Angreifer missbrauchen #ZeroClick-Lücke in #Zimbra | Security https://www.heise.de/news/Russische-Angreifer-missbrauchen-Zero-Click-Luecke-in-Zimbra-11376873.html #LaundryBear #VoidBlizzard #CLSTA1114 #TA488 #UNK_PitStop #CyberCrime #Patchday
-
Russische Angreifer missbrauchen #ZeroClick-Lücke in #Zimbra | Security https://www.heise.de/news/Russische-Angreifer-missbrauchen-Zero-Click-Luecke-in-Zimbra-11376873.html #LaundryBear #VoidBlizzard #CLSTA1114 #TA488 #UNK_PitStop #CyberCrime #Patchday
-
Russische Angreifer missbrauchen #ZeroClick-Lücke in #Zimbra | Security https://www.heise.de/news/Russische-Angreifer-missbrauchen-Zero-Click-Luecke-in-Zimbra-11376873.html #LaundryBear #VoidBlizzard #CLSTA1114 #TA488 #UNK_PitStop #CyberCrime #Patchday
-
Russische Angreifer missbrauchen #ZeroClick-Lücke in #Zimbra | Security https://www.heise.de/news/Russische-Angreifer-missbrauchen-Zero-Click-Luecke-in-Zimbra-11376873.html #LaundryBear #VoidBlizzard #CLSTA1114 #TA488 #UNK_PitStop #CyberCrime #Patchday
-
📰 Russian APT 'Laundry Bear' Targets West with Zero-Click Zimbra Exploit
International advisory warns of Russian APT 'Laundry Bear' using a zero-click Zimbra exploit (CVE-2025-66376) in a widespread espionage campaign against Western targets. Actors steal emails & credentials. #ThreatIntel #Zimbra #CyberSecurity
🌐 cyber[.]netsecops[.]io
-
📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.
Listen/Read: https://hackread.com/russian-hackers-zimbra-0-day-steal-emails-link-clicks/
-
📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.
Listen/Read: https://hackread.com/russian-hackers-zimbra-0-day-steal-emails-link-clicks/
-
📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.
Listen/Read: https://hackread.com/russian-hackers-zimbra-0-day-steal-emails-link-clicks/
-
📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.
Listen/Read: https://hackread.com/russian-hackers-zimbra-0-day-steal-emails-link-clicks/
-
📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.
Listen/Read: https://hackread.com/russian-hackers-zimbra-0-day-steal-emails-link-clicks/
-
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.
Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.
Reward: You've received a hollow Authenticator Token — pre-drained.
#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
-
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.
Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.
Reward: You've received a hollow Authenticator Token — pre-drained.
#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
-
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.
Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.
Reward: You've received a hollow Authenticator Token — pre-drained.
#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
-
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.
Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.
Reward: You've received a hollow Authenticator Token — pre-drained.
#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
-
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.
Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.
Reward: You've received a hollow Authenticator Token — pre-drained.
#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
-
Email Theft Campaign Exploits Zimbra Zero-Click Flaw
Pulse ID: 6a630d8195ebe8af82f8ade3
Pulse Link: https://otx.alienvault.com/pulse/6a630d8195ebe8af82f8ade3
Pulse Author: cryptocti
Created: 2026-07-24 07:00:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti
-
Email Theft Campaign Exploits Zimbra Zero-Click Flaw
Pulse ID: 6a630d8195ebe8af82f8ade3
Pulse Link: https://otx.alienvault.com/pulse/6a630d8195ebe8af82f8ade3
Pulse Author: cryptocti
Created: 2026-07-24 07:00:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti
-
Email Theft Campaign Exploits Zimbra Zero-Click Flaw
Pulse ID: 6a630d8195ebe8af82f8ade3
Pulse Link: https://otx.alienvault.com/pulse/6a630d8195ebe8af82f8ade3
Pulse Author: cryptocti
Created: 2026-07-24 07:00:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti
-
Email Theft Campaign Exploits Zimbra Zero-Click Flaw
Pulse ID: 6a630d8195ebe8af82f8ade3
Pulse Link: https://otx.alienvault.com/pulse/6a630d8195ebe8af82f8ade3
Pulse Author: cryptocti
Created: 2026-07-24 07:00:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti
-
Email Theft Campaign Exploits Zimbra Zero-Click Flaw
Pulse ID: 6a630d8195ebe8af82f8ade3
Pulse Link: https://otx.alienvault.com/pulse/6a630d8195ebe8af82f8ade3
Pulse Author: cryptocti
Created: 2026-07-24 07:00:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti
-
Zimbra Mailservers Targeted with Half-Click Exploits
Pulse ID: 6a62e8b79c1d4745bf2b24b5
Pulse Link: https://otx.alienvault.com/pulse/6a62e8b79c1d4745bf2b24b5
Pulse Author: Tr1sa111
Created: 2026-07-24 04:23:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111
-
Zimbra Mailservers Targeted with Half-Click Exploits
Pulse ID: 6a62e8b79c1d4745bf2b24b5
Pulse Link: https://otx.alienvault.com/pulse/6a62e8b79c1d4745bf2b24b5
Pulse Author: Tr1sa111
Created: 2026-07-24 04:23:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111
-
Zimbra Mailservers Targeted with Half-Click Exploits
Pulse ID: 6a62e8b79c1d4745bf2b24b5
Pulse Link: https://otx.alienvault.com/pulse/6a62e8b79c1d4745bf2b24b5
Pulse Author: Tr1sa111
Created: 2026-07-24 04:23:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111
-
Zimbra Mailservers Targeted with Half-Click Exploits
Pulse ID: 6a62e8b79c1d4745bf2b24b5
Pulse Link: https://otx.alienvault.com/pulse/6a62e8b79c1d4745bf2b24b5
Pulse Author: Tr1sa111
Created: 2026-07-24 04:23:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111
-
Zimbra Mailservers Targeted with Half-Click Exploits
Pulse ID: 6a62e8b79c1d4745bf2b24b5
Pulse Link: https://otx.alienvault.com/pulse/6a62e8b79c1d4745bf2b24b5
Pulse Author: Tr1sa111
Created: 2026-07-24 04:23:19Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Global Webmail Espionage
A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.
Pulse ID: 6a624073df6738006a6f6e5a
Pulse Link: https://otx.alienvault.com/pulse/6a624073df6738006a6f6e5a
Pulse Author: AlienVault
Created: 2026-07-23 16:25:23Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault
-
Zimbra Mailservers Targeted with Half-Click Exploits
Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.
Pulse ID: 6a6241a85c158acad5feb72c
Pulse Link: https://otx.alienvault.com/pulse/6a6241a85c158acad5feb72c
Pulse Author: AlienVault
Created: 2026-07-23 16:30:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault
-
Zimbra Mailservers Targeted with Half-Click Exploits
Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.
Pulse ID: 6a6241a85c158acad5feb72c
Pulse Link: https://otx.alienvault.com/pulse/6a6241a85c158acad5feb72c
Pulse Author: AlienVault
Created: 2026-07-23 16:30:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault
-
Zimbra Mailservers Targeted with Half-Click Exploits
Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.
Pulse ID: 6a6241a85c158acad5feb72c
Pulse Link: https://otx.alienvault.com/pulse/6a6241a85c158acad5feb72c
Pulse Author: AlienVault
Created: 2026-07-23 16:30:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault
-
Zimbra Mailservers Targeted with Half-Click Exploits
Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.
Pulse ID: 6a6241a85c158acad5feb72c
Pulse Link: https://otx.alienvault.com/pulse/6a6241a85c158acad5feb72c
Pulse Author: AlienVault
Created: 2026-07-23 16:30:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault
-
Zimbra Mailservers Targeted with Half-Click Exploits
Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.
Pulse ID: 6a6241a85c158acad5feb72c
Pulse Link: https://otx.alienvault.com/pulse/6a6241a85c158acad5feb72c
Pulse Author: AlienVault
Created: 2026-07-23 16:30:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault
-
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.
Pulse ID: 6a6241a95227e5bddd350d13
Pulse Link: https://otx.alienvault.com/pulse/6a6241a95227e5bddd350d13
Pulse Author: AlienVault
Created: 2026-07-23 16:30:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault
-
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.
Pulse ID: 6a6241a95227e5bddd350d13
Pulse Link: https://otx.alienvault.com/pulse/6a6241a95227e5bddd350d13
Pulse Author: AlienVault
Created: 2026-07-23 16:30:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault
-
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.
Pulse ID: 6a6241a95227e5bddd350d13
Pulse Link: https://otx.alienvault.com/pulse/6a6241a95227e5bddd350d13
Pulse Author: AlienVault
Created: 2026-07-23 16:30:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault
-
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.
Pulse ID: 6a6241a95227e5bddd350d13
Pulse Link: https://otx.alienvault.com/pulse/6a6241a95227e5bddd350d13
Pulse Author: AlienVault
Created: 2026-07-23 16:30:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault
-
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days
TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.
Pulse ID: 6a6241a95227e5bddd350d13
Pulse Link: https://otx.alienvault.com/pulse/6a6241a95227e5bddd350d13
Pulse Author: AlienVault
Created: 2026-07-23 16:30:33Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault
-
Patch Zimbra Collaboration Suite against CVE-2025-66376 immediately and monitor inbound mail for hidden JavaScript payloads originating from legitimate-looking compromised accounts.
Reward: A Certificate of Participation. It arrived via email. Do not open it.
#APT #Phishing #Zimbra #RussianHackers #CyberSecurity #ZeroDay (3/3)
-
Patch Zimbra Collaboration Suite against CVE-2025-66376 immediately and monitor inbound mail for hidden JavaScript payloads originating from legitimate-looking compromised accounts.
Reward: A Certificate of Participation. It arrived via email. Do not open it.
#APT #Phishing #Zimbra #RussianHackers #CyberSecurity #ZeroDay (3/3)
-
Kremlin Hackers Exploit Zimbra Bug to Infiltrate Networks
Kremlin hackers, also known as Laundry Bear, have been exploiting a vulnerability in the Zimbra Collaboration Suite to secretly infiltrate government and commercial networks for over a year, aiming to gather sensitive information for the Russian Federation. They've been using malicious emails to inject JavaScript code, allowing them to covertly acquire…