Hackers exploited Zimbra flaw as zero-day using iCalendar files
ID: 1e974191-ef1f-56a6-8d2f-5c240a6972f5
STIX ID: report--1e974191-ef1f-56a6-8d2f-5c240a6972f5
Feed Name: Bleeping Computer
Threat Score
Researchers observed a zero‑day XSS in Zimbra Collaboration Suite (CVE-2025-27915) abused via large .ICS calendar attachments containing obfuscated JavaScript that steals credentials, emails, contacts, and exfiltrates data; the attacks began in early January against at least one Brazilian military target and StrikeReady published IOCs and a deobfuscated payload after Zimbra released patches on January 27.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
