Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Cyber Group Targets Ukraine via Zimbra Flaw

Russian Cyber Group Targets Ukraine via Zimbra Flaw

Posted on March 19, 2026 By CWS

A Russian government-backed hacker group has been exploiting a severe cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite, targeting Ukraine, according to cybersecurity experts.

Zimbra Vulnerability Details

The vulnerability, identified as CVE-2025-66376 with a CVSS score of 7.2, was patched in November 2025 for Zimbra versions 10.1.13 and 10.0.18. This stored XSS issue allows attackers to use Cascading Style Sheets (CSS) @import directives in HTML emails, posing a security risk as highlighted in Zimbra’s advisory.

The lack of adequate sanitization for CSS content within HTML emails enables attackers to link to external resources or inject scripts executed when messages are opened in a browser. Successful exploitation could lead to remote code execution (RCE), compromising users’ email accounts and the Zimbra environment.

Impact and Exploitation by Threat Actors

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed CVE-2025-66376 in its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch the flaw within two weeks as per Binding Operational Directive (BOD) 22-01. Although CISA has not disclosed specific attack details, Seqrite Labs reports that Russian state-sponsored hackers have been using the vulnerability in attacks against Ukraine.

These attacks involve JavaScript embedded in email bodies that activate when opened, stealing data from victims’ email accounts. Seqrite Labs explains that the script operates quietly, extracting credentials, session tokens, backup 2FA codes, browser-saved passwords, and email content from the last 90 days, transmitting the data over DNS and HTTPS.

Operation GhostMail and Security Recommendations

One significant incident involved a phishing email received by a national infrastructure entity in Ukraine responsible for maritime and hydrographic support. This email, sent from a likely compromised account associated with a student from Ukraine’s National Academy of Internal Affairs, highlights the operation named GhostMail by Seqrite Labs.

Attributed to APT28, also known as Forest Blizzard, Fancy Bear, GruesomeLarch, and Sofacy, this campaign underscores the advanced tactics of Russian cyber operatives. Users are strongly advised to update their Zimbra installations promptly, as vulnerabilities in collaboration software are frequent targets for cyberattacks.

In January, another flaw, a local file inclusion (LFI) issue in Zimbra’s webmail UI, was noted for exploitation in targeted campaigns. It is crucial for organizations to remain vigilant and ensure their systems are updated to mitigate such cybersecurity threats.

Security Week News Tags:APT28, CISA, CVE-2025-66376, Cybersecurity, email security, Operation GhostMail, Russian cyber attack, Seqrite Labs, Ukraine, Zimbra vulnerability

Post navigation

Previous Post: Horabot Trojan Targets Mexico with Phishing Campaign
Next Post: Authorities Dismantle IoT Botnets Behind Massive DDoS Attacks

Related Posts

Apple Seeks Researchers for 2026 iPhone Security Program Apple Seeks Researchers for 2026 iPhone Security Program Security Week News
OpenAI Introduces Bug Bounty for AI Safety Risks OpenAI Introduces Bug Bounty for AI Safety Risks Security Week News
Chrome 150 and Firefox 152 Updates Fix Critical Bugs Chrome 150 and Firefox 152 Updates Fix Critical Bugs Security Week News
Over 1 Million Impacted by DaVita Data Breach Over 1 Million Impacted by DaVita Data Breach Security Week News
New ‘Reprompt’ Attack Silently Siphons Microsoft Copilot Data New ‘Reprompt’ Attack Silently Siphons Microsoft Copilot Data Security Week News
Firefox Bug Enables Tor User Tracking Firefox Bug Enables Tor User Tracking Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft
  • macOS Malware Steals Crypto via ClickFix Attacks
  • Malware Exploits Windows Hello Keys to Access Entra ID

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark