logo

Hackers exploit Roundcube webmail flaw to steal email, credentials

ID: 467dd75d-862c-521b-9737-722f155f0e72

STIX ID: report--467dd75d-862c-521b-9737-722f155f0e72

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-10-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors exploited a stored XSS in Roundcube (CVE-2024-37383) to deliver hidden, base64-encoded JavaScript inside emails that injects a fake login form to harvest Roundcube credentials and exfiltrate messages (via ManageSieve) to a remote host (libcdn.org); attacks targeted CIS government organizations and affect Roundcube versions prior to 1.5.7 and 1.6.7, with vendor patches available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.