Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Espionage Group Exploits Zimbra Flaw to Access Emails

Russian Espionage Group Exploits Zimbra Flaw to Access Emails

Posted on July 23, 2026 By CWS

A sophisticated Russian espionage group has been exploiting a vulnerability in Zimbra’s webmail client, allowing unauthorized access to Western email accounts. This security flaw, identified as CVE-2025-66376, had gone undetected for months, offering the attackers the ability to read communications and extract sensitive information such as email directories and two-factor authentication codes.

Exploiting the Zimbra Vulnerability

The espionage group targeted and compromised email systems using a stored cross-site scripting vulnerability in Zimbra’s Classic UI. This flaw allowed crafted HTML emails to execute JavaScript within authenticated sessions, giving attackers access to users’ email accounts without additional interaction. The vulnerability was actively used against Western government and commercial organizations from at least July 2025, as revealed by a joint advisory from the NSA, CISA, and other agencies.

Palo Alto Networks’ Unit 42 and Proofpoint provided detailed analyses of the campaign, highlighting how the attack required only viewing a malicious email to trigger the exploit. The attackers, tracked as TA488 by Proofpoint, utilized this vulnerability to infiltrate various sectors, including government, defense, and financial institutions across multiple regions.

Technical Details and Impact

The Zimbra flaw affected versions 10.0 before 10.0.18 and 10.1 before 10.1.13, with Zimbra releasing a patch on November 6, 2025. Despite this fix, compromised credentials remain a concern, as the patch does not revoke access already obtained through the exploit. The malicious payload, dubbed ZimReaper, was designed to steal CSRF tokens, browser-saved passwords, and two-factor authentication codes, exfiltrating data to attacker-controlled servers.

Unit 42 identified at least nine command-and-control (C2) servers used in the campaign, with each server remaining active for an average of 35.4 days. The exploit also involved embedding malicious code within email HTML content, which Zimbra’s sanitizer failed to detect as executable.

Mitigation and Ongoing Threats

Organizations are urged to upgrade Zimbra deployments to version 10.1.13 or later and to conduct thorough reviews of potentially compromised accounts. This includes resetting passwords, invalidating active sessions, and checking for signs of unauthorized access. Security researchers recommend using Proofpoint’s YARA rules to detect the exploit’s unique patterns in email HTML.

While Proofpoint noted a decline in activity from TA488 post-February 2026, the threat remains as attackers may continue targeting unpatched systems. The advisory emphasizes the importance of maintaining updated security measures to prevent further exploitation. Additionally, the ongoing assessment of the espionage group’s tactics underscores the need for vigilance and proactive cybersecurity strategies.

As organizations work to secure their systems, understanding the techniques and vulnerabilities exploited in this campaign is crucial for strengthening defenses against similar threats in the future.

The Hacker News Tags:CISA, CVE-2025-66376, cyber attack, Cybersecurity, email security, NSA, Proofpoint, Russian espionage, TA488, two-factor authentication, Unit 42, Vulnerability, webmail client, Zimbra

Post navigation

Previous Post: Hackers Exploit Notepad++ Plugins for Silent System Breach
Next Post: Chaos Ransomware Exploits Browsers as Secret Command Channels

Related Posts

SharePoint Vulnerability Abused After PoC Emerges SharePoint Vulnerability Abused After PoC Emerges The Hacker News
Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing The Hacker News
Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup The Hacker News
Compromised Nx Console Targets VS Code with Credential Theft Compromised Nx Console Targets VS Code with Credential Theft The Hacker News
Cellebrite Tools Used on Activist’s iPhone in Russia Cellebrite Tools Used on Activist’s iPhone in Russia The Hacker News
Silver Fox Targets India and Russia with ABCDoor Malware Silver Fox Targets India and Russia with ABCDoor Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CrowdStrike Debuts SafeMind: Innovative AI Cybersecurity
  • MikroTik RouterOS Flaw Exploited: Urgent Patch Required
  • Critical Flaw in ASUS Control Center Exposes Systems
  • REVSTEALER Modules Disable Security to Run Crypto Miner
  • MikroTik Routers Vulnerable to Unauthenticated SSH Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark