Russian espionage used a Zimbra webmail zero-day to steal emails and 2FA codes
Source headline: Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Intelligence Summary
A Russian state-supported espionage group exploited a then-unknown vulnerability in Zimbra’s webmail client. The flaw allowed them to read messages from Western mailboxes over an extended period. Their payload focused on recent email and also targeted sensitive data such as stored browser passwords and two-factor recovery codes. Opening a message was enough to trigger the malicious activity. This increases the risk of account takeover, even when 2FA is enabled, so organizations should urgently review Zimbra patching and threat detection guidance.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.