logo

Cyberattackers Exploit Zimbra Zero-Day Via ICS

ID: f4a44251-06cd-5c28-9025-055927b86b5e

STIX ID: report--f4a44251-06cd-5c28-9025-055927b86b5e

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-10-06

Date Updated: 2026-05-05

Author: Jai Vijayan, Contributing Writer

...
...

StrikeReady Labs observed a targeted cyberespionage campaign that used a malicious ICS calendar file, masquerading as the Libyan Navy’s Office of Protocol, to exploit an XSS zero-day (CVE-2025-27915) in Zimbra Classic Web client. The injected JavaScript acted as a multi-function infostealer — harvesting credentials, emails, contacts, and MFA-related data, manipulating Zimbra mail filters to exfiltrate messages, and employing obfuscation and timing delays to evade detection; Zimbra issued a patch (ZCS 10.1.9) in June.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.