< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-24T00:06:08+05:30

Russian Espionage Group Exploits Zimbra Zero-Day to Steal Email and 2FA Credentials

A Russian state-sponsored group exploited a zero-day vulnerability in Zimbra's webmail client to steal emails and 2FA codes by leveraging stored cross-site scripting. The NSA and CISA issued a joint advisory, urging immediate patching and account reviews to mitigate ongoing threats.

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client.

The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.

The NSA, CISA and partner agencies published

Read original article

*** END OF TRANSMISSION ***