NSA, CISA and partners report a Russian state-supported group exploited a Zimbra webmail zero-day to steal mail, credentials and 2FA codes — opening or previewing the message was enough. If you run Zimbra, review the advisory and harden now.Cyber Resilience desk
Sources (2)
- hackernews · hackernews
- hackread · hackread
What this means for you — CISO:If you run Zimbra, apply the fixed build now, review the joint NSA/CISA advisory, and hunt mail and identity logs for theft of recent mail, directory data, saved passwords, and 2FA recovery codes.
What this means for you — Lean IT orgs:If your email is on Zimbra, update it today or ask whoever hosts it whether the fix is in—opening or previewing a message was enough to steal mail and 2FA backup codes.
What this means for you — MSP:Inventory every client on Zimbra, push the patched version, and search mail and identity telemetry for IOCs from this campaign across tenants.
What this means for you — Researcher:Use the joint advisory for the Zimbra webmail zero-day details, zero-click open/preview trigger, payload scope (≈90 days of mail, directory, browser-saved passwords, 2FA recovery codes), and TA488 attribution.