Security · 1h ago
Russian hackers expand half-click email attack from Zimbra to Outlook
Russian state-sponsored hackers have adapted their 'half-click' email attack from Zimbra to target Microsoft Outlook users. Opening a malicious message triggers a browser implant that persists across password changes and device rebuilds. The technique exploits a known vulnerability and requires minimal user interaction.
Meridian48 take
The shift to Outlook broadens the attack surface significantly, but the reliance on a browser implant limits its reach to web-based email clients.
Read the full reporting
Russian spies take their half-click email attack from Zimbra to Outlook →
The Register
russian-hackersemail-attack