SECURITYTHE HACKER NEWS
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported espionage group exploited a previously unknown vulnerability in Zimbra's webmail client to steal emails, password data, and two-factor authentication recovery codes. The attack, which targeted the last 90 days of email and an organization's directory, was disclosed by the NSA, CISA, and partner agencies.
Mentioned
Related Signal
Adjacent reporting
- Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
- Russia Hacked Routers to Steal Microsoft Office Tokens
- FBI: Russian hackers now target Signal backup recovery keys
- Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
- Hackers used AI to craft zero-day attack to bypass 2FA: Google