Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Cyber Group Targets Ukraine via Zimbra Flaw

Russian Cyber Group Targets Ukraine via Zimbra Flaw

Posted on March 19, 2026 By CWS

A Russian government-backed hacker group has been exploiting a severe cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite, targeting Ukraine, according to cybersecurity experts.

Zimbra Vulnerability Details

The vulnerability, identified as CVE-2025-66376 with a CVSS score of 7.2, was patched in November 2025 for Zimbra versions 10.1.13 and 10.0.18. This stored XSS issue allows attackers to use Cascading Style Sheets (CSS) @import directives in HTML emails, posing a security risk as highlighted in Zimbra’s advisory.

The lack of adequate sanitization for CSS content within HTML emails enables attackers to link to external resources or inject scripts executed when messages are opened in a browser. Successful exploitation could lead to remote code execution (RCE), compromising users’ email accounts and the Zimbra environment.

Impact and Exploitation by Threat Actors

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed CVE-2025-66376 in its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch the flaw within two weeks as per Binding Operational Directive (BOD) 22-01. Although CISA has not disclosed specific attack details, Seqrite Labs reports that Russian state-sponsored hackers have been using the vulnerability in attacks against Ukraine.

These attacks involve JavaScript embedded in email bodies that activate when opened, stealing data from victims’ email accounts. Seqrite Labs explains that the script operates quietly, extracting credentials, session tokens, backup 2FA codes, browser-saved passwords, and email content from the last 90 days, transmitting the data over DNS and HTTPS.

Operation GhostMail and Security Recommendations

One significant incident involved a phishing email received by a national infrastructure entity in Ukraine responsible for maritime and hydrographic support. This email, sent from a likely compromised account associated with a student from Ukraine’s National Academy of Internal Affairs, highlights the operation named GhostMail by Seqrite Labs.

Attributed to APT28, also known as Forest Blizzard, Fancy Bear, GruesomeLarch, and Sofacy, this campaign underscores the advanced tactics of Russian cyber operatives. Users are strongly advised to update their Zimbra installations promptly, as vulnerabilities in collaboration software are frequent targets for cyberattacks.

In January, another flaw, a local file inclusion (LFI) issue in Zimbra’s webmail UI, was noted for exploitation in targeted campaigns. It is crucial for organizations to remain vigilant and ensure their systems are updated to mitigate such cybersecurity threats.

Security Week News Tags:APT28, CISA, CVE-2025-66376, Cybersecurity, email security, Operation GhostMail, Russian cyber attack, Seqrite Labs, Ukraine, Zimbra vulnerability

Post navigation

Previous Post: Horabot Trojan Targets Mexico with Phishing Campaign
Next Post: Authorities Dismantle IoT Botnets Behind Massive DDoS Attacks

Related Posts

Microsoft to Lay Off About 3% of Its Workforce Microsoft to Lay Off About 3% of Its Workforce Security Week News
Cisco Patches Critical Vulnerabilities in Contact Center Appliance Cisco Patches Critical Vulnerabilities in Contact Center Appliance Security Week News
Check Point Boosts AI Security with New Acquisitions Check Point Boosts AI Security with New Acquisitions Security Week News
Apple Rolls Out iOS 26, macOS Tahoe 26 With Patches for Over 50 Vulnerabilities Apple Rolls Out iOS 26, macOS Tahoe 26 With Patches for Over 50 Vulnerabilities Security Week News
Spanish Authorities Dismantle ‘GXC Team’ Crime-as-a-Service Operation Spanish Authorities Dismantle ‘GXC Team’ Crime-as-a-Service Operation Security Week News
Surveillance Firm Bypasses SS7 Protections to Retrieve User Location Surveillance Firm Bypasses SS7 Protections to Retrieve User Location Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SplitVPN Breach Exposes User Data, Raises Privacy Concerns
  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SplitVPN Breach Exposes User Data, Raises Privacy Concerns
  • Adform’s Ad Platform Breached to Distribute Crypto Malware
  • Brinks Home Confirms Major Data Breach Amid Hacker Claims
  • Flaw in Coldcard Wallet Triggers $70 Million Bitcoin Heist
  • Top Web Application Firewalls for 2026: Expert Ranking

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark