Russian Spy Group Exploits Zimbra Zero-Day to Steal Mail, Passwords and 2FA Codes

TL;DR Summary
A Russian state-backed espionage group exploited a stored cross-site scripting flaw in Zimbra's Classic UI (CVE-2025-66376) to automatically render a malicious email in an authenticated webmail session, stealing CSRF tokens, browser-saved passwords, and 2FA scratch codes, and exfiltrating 90 days of mail; patching the vulnerability is necessary but does not revoke credentials, so organizations should patch, reset passwords, invalidate sessions, review for the ZimbraWeb app-specific password, and monitor for identified indicators of compromise.
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes The Hacker News
- TA488 Targets Zimbra Mailservers with Half-Click Exploits Proofpoint
- New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors CNN
- US and allies say Russian hackers stole emails without social engineering Reuters
- UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations National Cyber Security Centre
Reading Insights
Total Reads
1
Unique Readers
4
Time Saved
5 min
vs 6 min read
Condensed
93%
1,097 → 73 words
Want the full story? Read the original article
Read on The Hacker News