#Zimbra Collaboration Suite

[ follow ]
#cybersecurity
Dark Reading
6 months ago
Privacy professionals

APTs Swarm Zimbra Zero-Day to Steal Government Info Worldwide

Four separate cyberattack groups have exploited a zero-day security vulnerability in the Zimbra Collaboration Suite to steal email data and credentials.
The attacks targeted government organizations in Greece, Moldova, Tunisia, Vietnam, and Pakistan.
The vulnerability was patched in July, but the attacks began before the patch was available. [ more ]
Dark Reading
6 months ago
Privacy professionals

APTs Swarm Zimbra Zero-Day to Steal Government Info Worldwide

Four separate cyberattack groups have exploited a zero-day security vulnerability in the Zimbra Collaboration Suite to steal email data and credentials.
The attacks targeted government organizations in Greece, Moldova, Tunisia, Vietnam, and Pakistan.
The vulnerability was patched in July, but the attacks began before the patch was available. [ more ]
morecybersecurity
#zero-day vulnerability
SecurityWeek
6 months ago
Privacy professionals

Zimbra Zero-Day Exploited to Hack Government Emails

A Zimbra Collaboration Suite zero-day vulnerability was exploited to steal email data from government organizations in multiple countries.
The exploit, tracked as CVE-2023-37580, is a reflected cross-site scripting (XSS) bug that requires the user to click on a malicious link.
Google's Threat Analysis Group observed multiple campaigns exploiting the zero-day and linked the attacks to a Russian APT known as Winter Vivern. [ more ]
SecurityWeek
6 months ago
Privacy professionals

Zimbra Zero-Day Exploited to Hack Government Emails

A Zimbra Collaboration Suite zero-day vulnerability was exploited to steal email data from government organizations in multiple countries.
The exploit, tracked as CVE-2023-37580, is a reflected cross-site scripting (XSS) bug that requires the user to click on a malicious link.
Google's Threat Analysis Group observed multiple campaigns exploiting the zero-day and linked the attacks to a Russian APT known as Winter Vivern. [ more ]
morezero-day vulnerability
[ Load more ]