Security · 1h ago
Russian Hackers Exploited Zimbra Zero-Day to Steal Emails and 2FA Codes
A Russian state-sponsored group exploited a zero-day vulnerability in Zimbra's webmail client to access Western mailboxes. The attack stole the last 90 days of emails, the full directory, saved passwords, and two-factor recovery codes. Opening the malicious message was enough to trigger the exploit, according to the NSA and CISA.
Meridian48 take
The attack's ability to bypass 2FA by stealing recovery codes underscores a critical weakness in relying on browser-based authentication.
Read the full reporting
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes →
The Hacker News
zimbra-zero-dayrussian-espionage