logo

Hackers exploited Zimbra flaw as zero-day using iCalendar files

ID: 1e974191-ef1f-56a6-8d2f-5c240a6972f5

STIX ID: report--1e974191-ef1f-56a6-8d2f-5c240a6972f5

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers observed a zero‑day XSS in Zimbra Collaboration Suite (CVE-2025-27915) abused via large .ICS calendar attachments containing obfuscated JavaScript that steals credentials, emails, contacts, and exfiltrates data; the attacks began in early January against at least one Brazilian military target and StrikeReady published IOCs and a deobfuscated payload after Zimbra released patches on January 27.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.