Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client.

The payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.

The NSA, CISA and partner agencies published

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Tell HN: Installing Cursor on iOS irreversibly changes your privacy settings

Tell HN: Installing Cursor on iOS irreversibly changes your privacy settings Source: Hacker News

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware

Attack Update: Top 5 Attack-IPs auf doode.info – 16.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 74 requests (recent log) 170.130.202.46 — 47 requests (recent log) 54.154.120.116 — 30 requests (recent