Cyberattackers Exploit Zimbra Zero-Day Via ICS
ID: f4a44251-06cd-5c28-9025-055927b86b5e
STIX ID: report--f4a44251-06cd-5c28-9025-055927b86b5e
Feed Name: Dark Reading
StrikeReady Labs observed a targeted cyberespionage campaign that used a malicious ICS calendar file, masquerading as the Libyan Navy’s Office of Protocol, to exploit an XSS zero-day (CVE-2025-27915) in Zimbra Classic Web client. The injected JavaScript acted as a multi-function infostealer — harvesting credentials, emails, contacts, and MFA-related data, manipulating Zimbra mail filters to exfiltrate messages, and employing obfuscation and timing delays to evade detection; Zimbra issued a patch (ZCS 10.1.9) in June.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
