ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

Russian espionage used a Zimbra webmail zero-day to steal emails and 2FA codes

Source headline: Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

A Russian state-supported espionage group exploited a then-unknown vulnerability in Zimbra’s webmail client. The flaw allowed them to read messages from Western mailboxes over an extended period. Their payload focused on recent email and also targeted sensitive data such as stored browser passwords and two-factor recovery codes. Opening a message was enough to trigger the malicious activity. This increases the risk of account takeover, even when 2FA is enabled, so organizations should urgently review Zimbra patching and threat detection guidance.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#zero-day #espionage #webmail #zimbra #2fa #mailbox-theft
Original reporting The Hacker News Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Open original source