Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Espionage Group Exploits Zimbra Flaw to Access Emails

Russian Espionage Group Exploits Zimbra Flaw to Access Emails

Posted on July 23, 2026 By CWS

A sophisticated Russian espionage group has been exploiting a vulnerability in Zimbra’s webmail client, allowing unauthorized access to Western email accounts. This security flaw, identified as CVE-2025-66376, had gone undetected for months, offering the attackers the ability to read communications and extract sensitive information such as email directories and two-factor authentication codes.

Exploiting the Zimbra Vulnerability

The espionage group targeted and compromised email systems using a stored cross-site scripting vulnerability in Zimbra’s Classic UI. This flaw allowed crafted HTML emails to execute JavaScript within authenticated sessions, giving attackers access to users’ email accounts without additional interaction. The vulnerability was actively used against Western government and commercial organizations from at least July 2025, as revealed by a joint advisory from the NSA, CISA, and other agencies.

Palo Alto Networks’ Unit 42 and Proofpoint provided detailed analyses of the campaign, highlighting how the attack required only viewing a malicious email to trigger the exploit. The attackers, tracked as TA488 by Proofpoint, utilized this vulnerability to infiltrate various sectors, including government, defense, and financial institutions across multiple regions.

Technical Details and Impact

The Zimbra flaw affected versions 10.0 before 10.0.18 and 10.1 before 10.1.13, with Zimbra releasing a patch on November 6, 2025. Despite this fix, compromised credentials remain a concern, as the patch does not revoke access already obtained through the exploit. The malicious payload, dubbed ZimReaper, was designed to steal CSRF tokens, browser-saved passwords, and two-factor authentication codes, exfiltrating data to attacker-controlled servers.

Unit 42 identified at least nine command-and-control (C2) servers used in the campaign, with each server remaining active for an average of 35.4 days. The exploit also involved embedding malicious code within email HTML content, which Zimbra’s sanitizer failed to detect as executable.

Mitigation and Ongoing Threats

Organizations are urged to upgrade Zimbra deployments to version 10.1.13 or later and to conduct thorough reviews of potentially compromised accounts. This includes resetting passwords, invalidating active sessions, and checking for signs of unauthorized access. Security researchers recommend using Proofpoint’s YARA rules to detect the exploit’s unique patterns in email HTML.

While Proofpoint noted a decline in activity from TA488 post-February 2026, the threat remains as attackers may continue targeting unpatched systems. The advisory emphasizes the importance of maintaining updated security measures to prevent further exploitation. Additionally, the ongoing assessment of the espionage group’s tactics underscores the need for vigilance and proactive cybersecurity strategies.

As organizations work to secure their systems, understanding the techniques and vulnerabilities exploited in this campaign is crucial for strengthening defenses against similar threats in the future.

The Hacker News Tags:CISA, CVE-2025-66376, cyber attack, Cybersecurity, email security, NSA, Proofpoint, Russian espionage, TA488, two-factor authentication, Unit 42, Vulnerability, webmail client, Zimbra

Post navigation

Previous Post: Hackers Exploit Notepad++ Plugins for Silent System Breach
Next Post: Chaos Ransomware Exploits Browsers as Secret Command Channels

Related Posts

Critical WordPress Flaw Allows Code Execution Critical WordPress Flaw Allows Code Execution The Hacker News
Fortinet Updates Fix Major SQL Injection Vulnerability Fortinet Updates Fix Major SQL Injection Vulnerability The Hacker News
A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do The Hacker News
ClickFix Campaigns Exploit Fake AI Tools to Spread MacSync ClickFix Campaigns Exploit Fake AI Tools to Spread MacSync The Hacker News
ShapedPlugin WordPress Plugins Hit by Supply Chain Attack ShapedPlugin WordPress Plugins Hit by Supply Chain Attack The Hacker News
PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chaos Ransomware Exploits Browsers as Secret Command Channels
  • Russian Espionage Group Exploits Zimbra Flaw to Access Emails
  • Hackers Exploit Notepad++ Plugins for Silent System Breach
  • China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks
  • Next.js Addresses Critical Security Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chaos Ransomware Exploits Browsers as Secret Command Channels
  • Russian Espionage Group Exploits Zimbra Flaw to Access Emails
  • Hackers Exploit Notepad++ Plugins for Silent System Breach
  • China-Linked JadeProx Unveils TriBack Loader in Cyber Attacks
  • Next.js Addresses Critical Security Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark