Russian hackers exploit Zimbra flaw in Ukrainian govt attacks
ID: 88e7851a-0831-52c0-9a74-2a33fb914dd6
STIX ID: report--88e7851a-0831-52c0-9a74-2a33fb914dd6
Feed Name: Bleeping Computer
Threat Score
APT28 (Fancy Bear) is actively exploiting a high-severity stored XSS in Zimbra (CVE-2025-66376) to achieve RCE and silently harvest credentials, session tokens, 2FA backup codes, saved passwords, and up to 90 days of mailbox contents from targeted Ukrainian government recipients (Operation GhostMail); CISA has cataloged the vulnerability and ordered remediation while researchers have documented exfiltration over DNS and HTTPS.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
