home.social

#zimbra — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zimbra, aggregated by home.social.

fetched live
  1. Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    Indicators extracted from public reporting. Source: media.defense.gov/2026/Jul/22/

    Pulse ID: 6a79ace8ce2eec075b55ddb0
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:50:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL

  2. Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    Indicators extracted from public reporting. Source: media.defense.gov/2026/Jul/22/

    Pulse ID: 6a79ace8ce2eec075b55ddb0
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:50:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL

  3. Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    Indicators extracted from public reporting. Source: media.defense.gov/2026/Jul/22/

    Pulse ID: 6a79ace8ce2eec075b55ddb0
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:50:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL

  4. Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    Indicators extracted from public reporting. Source: media.defense.gov/2026/Jul/22/

    Pulse ID: 6a79ace8ce2eec075b55ddb0
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:50:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL

  5. Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    Indicators extracted from public reporting. Source: media.defense.gov/2026/Jul/22/

    Pulse ID: 6a79ace8ce2eec075b55ddb0
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:50:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #PDF #Phishing #RCE #Russia #Zimbra #bot #CyberHunter_NL

  6. Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!

    Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
    Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
    Payload zdekodowany przez Proofpoint
    Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
    Rosjanie próbowali wykradać:

    wiadomości z ostatnich 90 dni,
    książkę adresową organizacji,
    hasła podpowiadane przez przeglądarkę,
    awaryjne kody 2FA i token CSRF,

    Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
    Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]

    #AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra

    niebezpiecznik.pl/post/rosjani

  7. Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!

    Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
    Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
    Payload zdekodowany przez Proofpoint
    Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
    Rosjanie próbowali wykradać:

    wiadomości z ostatnich 90 dni,
    książkę adresową organizacji,
    hasła podpowiadane przez przeglądarkę,
    awaryjne kody 2FA i token CSRF,

    Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
    Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]

    #AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra

    niebezpiecznik.pl/post/rosjani

  8. Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!

    Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
    Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
    Payload zdekodowany przez Proofpoint
    Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
    Rosjanie próbowali wykradać:

    wiadomości z ostatnich 90 dni,
    książkę adresową organizacji,
    hasła podpowiadane przez przeglądarkę,
    awaryjne kody 2FA i token CSRF,

    Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
    Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]

    #AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra

    niebezpiecznik.pl/post/rosjani

  9. Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!

    Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
    Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
    Payload zdekodowany przez Proofpoint
    Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
    Rosjanie próbowali wykradać:

    wiadomości z ostatnich 90 dni,
    książkę adresową organizacji,
    hasła podpowiadane przez przeglądarkę,
    awaryjne kody 2FA i token CSRF,

    Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
    Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]

    #AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra

    niebezpiecznik.pl/post/rosjani

  10. Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!

    Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
    Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
    Payload zdekodowany przez Proofpoint
    Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
    Rosjanie próbowali wykradać:

    wiadomości z ostatnich 90 dni,
    książkę adresową organizacji,
    hasła podpowiadane przez przeglądarkę,
    awaryjne kody 2FA i token CSRF,

    Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
    Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]

    #AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra

    niebezpiecznik.pl/post/rosjani

  11. Reward: Congratulations! You've received a Loot Box containing your own sent folder, read receipts, and attachments. Non-transferable. Non-refundable. Already transferred.

    #Cybersecurity #RussianHackers #Zimbra #EmailSecurity #ZeroDay #NoSocialEngineeringNeeded (3/3)

  12. Reward: Congratulations! You've received a Loot Box containing your own sent folder, read receipts, and attachments. Non-transferable. Non-refundable. Already transferred.

    #Cybersecurity #RussianHackers #Zimbra #EmailSecurity #ZeroDay #NoSocialEngineeringNeeded (3/3)

  13. 📰 Russian APT 'Laundry Bear' Targets West with Zero-Click Zimbra Exploit

    International advisory warns of Russian APT 'Laundry Bear' using a zero-click Zimbra exploit (CVE-2025-66376) in a widespread espionage campaign against Western targets. Actors steal emails & credentials. #ThreatIntel #Zimbra #CyberSecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ru

  14. 📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

    Listen/Read: hackread.com/russian-hackers-z

  15. 📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

    Listen/Read: hackread.com/russian-hackers-z

    #CyberSecurity #Zimbra #0day #Vulnerability #Russia #TA488

  16. 📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

    Listen/Read: hackread.com/russian-hackers-z

    #CyberSecurity #Zimbra #0day #Vulnerability #Russia #TA488

  17. 📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

    Listen/Read: hackread.com/russian-hackers-z

    #CyberSecurity #Zimbra #0day #Vulnerability #Russia #TA488

  18. 📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

    Listen/Read: hackread.com/russian-hackers-z

    #CyberSecurity #Zimbra #0day #Vulnerability #Russia #TA488

  19. CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

    Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

    Reward: You've received a hollow Authenticator Token — pre-drained.

    #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

  20. CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

    Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

    Reward: You've received a hollow Authenticator Token — pre-drained.

    #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

  21. CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

    Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

    Reward: You've received a hollow Authenticator Token — pre-drained.

    #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

  22. CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

    Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

    Reward: You've received a hollow Authenticator Token — pre-drained.

    #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

  23. CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

    Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

    Reward: You've received a hollow Authenticator Token — pre-drained.

    #ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

  24. Email Theft Campaign Exploits Zimbra Zero-Click Flaw

    Pulse ID: 6a630d8195ebe8af82f8ade3
    Pulse Link: otx.alienvault.com/pulse/6a630
    Pulse Author: cryptocti
    Created: 2026-07-24 07:00:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti

  25. Email Theft Campaign Exploits Zimbra Zero-Click Flaw

    Pulse ID: 6a630d8195ebe8af82f8ade3
    Pulse Link: otx.alienvault.com/pulse/6a630
    Pulse Author: cryptocti
    Created: 2026-07-24 07:00:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti

  26. Email Theft Campaign Exploits Zimbra Zero-Click Flaw

    Pulse ID: 6a630d8195ebe8af82f8ade3
    Pulse Link: otx.alienvault.com/pulse/6a630
    Pulse Author: cryptocti
    Created: 2026-07-24 07:00:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti

  27. Email Theft Campaign Exploits Zimbra Zero-Click Flaw

    Pulse ID: 6a630d8195ebe8af82f8ade3
    Pulse Link: otx.alienvault.com/pulse/6a630
    Pulse Author: cryptocti
    Created: 2026-07-24 07:00:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti

  28. Email Theft Campaign Exploits Zimbra Zero-Click Flaw

    Pulse ID: 6a630d8195ebe8af82f8ade3
    Pulse Link: otx.alienvault.com/pulse/6a630
    Pulse Author: cryptocti
    Created: 2026-07-24 07:00:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Email #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #cryptocti

  29. Zimbra Mailservers Targeted with Half-Click Exploits

    Pulse ID: 6a62e8b79c1d4745bf2b24b5
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:23:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111

  30. Zimbra Mailservers Targeted with Half-Click Exploits

    Pulse ID: 6a62e8b79c1d4745bf2b24b5
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:23:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111

  31. Zimbra Mailservers Targeted with Half-Click Exploits

    Pulse ID: 6a62e8b79c1d4745bf2b24b5
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:23:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111

  32. Zimbra Mailservers Targeted with Half-Click Exploits

    Pulse ID: 6a62e8b79c1d4745bf2b24b5
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:23:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111

  33. Zimbra Mailservers Targeted with Half-Click Exploits

    Pulse ID: 6a62e8b79c1d4745bf2b24b5
    Pulse Link: otx.alienvault.com/pulse/6a62e
    Pulse Author: Tr1sa111
    Created: 2026-07-24 04:23:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Zimbra #bot #Tr1sa111

  34. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  35. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  36. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  37. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  38. Global Webmail Espionage

    A persistent cyberespionage campaign tracked as CL-STA-1114, overlapping with Russian threat actor activity known as Void Blizzard and LAUNDRY BEAR, has been targeting Zimbra webmail in government, defense, transportation, and financial organizations. The campaign focuses on NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Attackers exploit CVE-2025-66376, a vulnerability in Zimbra Collaboration Suite, using zero-click phishing emails that automatically inject malicious JavaScript payloads without user interaction. The payload exfiltrates sensitive data including login credentials, email archives, CSRF tokens, 2FA scratch codes, and 90 days of email history to command and control servers. Active since 2024, the campaign targeting Zimbra servers began in July 2025, utilizing HTML attachments with obfuscated Base64-encoded scripts that deploy SVG elements to inject the JavaScript into victims' browsers.

    Pulse ID: 6a624073df6738006a6f6e5a
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:25:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #Africa #Browser #CyberSecurity #Cyberespionage #Email #Espionage #Government #HTML #InfoSec #Java #JavaScript #NATO #OTX #OpenThreatExchange #Phishing #RAT #Russia #SVG #UK #Ukr #Ukraine #Vulnerability #Webmail #Zimbra #bot #AlienVault

  39. Zimbra Mailservers Targeted with Half-Click Exploits

    Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.

    Pulse ID: 6a6241a85c158acad5feb72c
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault

  40. Zimbra Mailservers Targeted with Half-Click Exploits

    Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.

    Pulse ID: 6a6241a85c158acad5feb72c
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault

  41. Zimbra Mailservers Targeted with Half-Click Exploits

    Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.

    Pulse ID: 6a6241a85c158acad5feb72c
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault

  42. Zimbra Mailservers Targeted with Half-Click Exploits

    Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.

    Pulse ID: 6a6241a85c158acad5feb72c
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault

  43. Zimbra Mailservers Targeted with Half-Click Exploits

    Russian-aligned threat actor TA488, also known as Void Blizzard and Laundry Bear, exploited a previously unknown vulnerability in Zimbra Collaboration Suite mailservers for at least five months during 2025. The vulnerability, later assigned CVE-2025-66376, was leveraged through half-click exploits embedded in HTML emails that executed upon opening without requiring user interaction. Upon successful exploitation, TA488 deployed ZimReaper malware to establish persistent access, steal credentials and two-factor authentication codes, and exfiltrate emails via DNS tunneling and HTTP requests. The campaigns primarily targeted Ukrainian government entities, alongside U.S. government, nuclear science facilities, and defense industrial base organizations. The actor used domains spoofing Zimbra telemetry services and regularly updated obfuscation techniques to evade detection. TA488 is believed to be a private contractor working for Russian intelligence services.

    Pulse ID: 6a6241a85c158acad5feb72c
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DNS #Email #Government #HTML #HTTP #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Russia #UK #Ukr #Ukrainian #Vulnerability #Zimbra #bot #AlienVault

  44. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

    Pulse ID: 6a6241a95227e5bddd350d13
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault

  45. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

    Pulse ID: 6a6241a95227e5bddd350d13
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault

  46. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

    Pulse ID: 6a6241a95227e5bddd350d13
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault

  47. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

    Pulse ID: 6a6241a95227e5bddd350d13
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault

  48. Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days

    TA458, a Russia-aligned espionage group likely linked to GRU, continues exploiting half-click cross-site scripting vulnerabilities in webmail platforms to steal sensitive email data. These exploits require no user interaction beyond opening the malicious email in webmail. The actor exploited multiple zero-days including SOGo (CVE-2026-8496), Zimbra (CVE-2025-27915), and mDaemon (CVE-2025-3929), alongside n-day Roundcube vulnerabilities. TA458 deploys SpyPress malware, an obfuscated JavaScript-based tool customized for each targeted mailserver, stealing credentials, contacts, and emails. The group primarily targets Ukrainian government entities and Eastern European military installations across Albania, Greece, Moldova, and Türkiye, with occasional focus on chemical, telecommunications, and technology sectors. Recent variants include backdoor mechanisms for persistent access through reverse shells and webshells.

    Pulse ID: 6a6241a95227e5bddd350d13
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Albania #BackDoor #CyberSecurity #EasternEurope #Email #Espionage #Europe #Government #InfoSec #Java #JavaScript #Malware #Military #OTX #OpenThreatExchange #RAT #Russia #SMS #Telecom #Telecommunication #UK #Ukr #Ukrainian #Webmail #ZeroDay #Zimbra #bot #AlienVault

  49. Patch Zimbra Collaboration Suite against CVE-2025-66376 immediately and monitor inbound mail for hidden JavaScript payloads originating from legitimate-looking compromised accounts.

    Reward: A Certificate of Participation. It arrived via email. Do not open it.

    #APT #Phishing #Zimbra #RussianHackers #CyberSecurity #ZeroDay (3/3)

  50. Patch Zimbra Collaboration Suite against CVE-2025-66376 immediately and monitor inbound mail for hidden JavaScript payloads originating from legitimate-looking compromised accounts.

    Reward: A Certificate of Participation. It arrived via email. Do not open it.

    #APT #Phishing #Zimbra #RussianHackers #CyberSecurity #ZeroDay (3/3)

  51. Kremlin Hackers Exploit Zimbra Bug to Infiltrate Networks

    Kremlin hackers, also known as Laundry Bear, have been exploiting a vulnerability in the Zimbra Collaboration Suite to secretly infiltrate government and commercial networks for over a year, aiming to gather sensitive information for the Russian Federation. They've been using malicious emails to inject JavaScript code, allowing them to covertly acquire…

    osintsights.com/kremlin-hacker

    #LaundryBear #Russia #Cve202566376 #Zimbra #NationState