logo

Sednit abuses XSS flaws to hit gov't entities, defense companies

ID: 61e0105f-c743-51b2-8e6b-44261965699f

STIX ID: report--61e0105f-c743-51b2-8e6b-44261965699f

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2025-05-15

Date Updated: 2026-05-01

...
...

ESET researchers uncovered "Operation RoundPress", a targeted cyberespionage campaign likely conducted by the Russia-aligned Sednit APT that exploits XSS vulnerabilities — including a zero-day in MDaemon webmail — to steal emails from Ukrainian government accounts and European defense contractors. The attackers targeted multiple webmail platforms (Roundcube, Horde, MDaemon, Zimbra) and sometimes bypassed two-factor authentication to exfiltrate confidential information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.