Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Read full story on The Hacker News
Share
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
AI disclosure

Summary

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The NSA, CISA and partner agencies published

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.