CVE-2025-66376: Russian APT Exploits Zimbra Zero-Day
ID: f6700bd5-c99e-5878-ad2c-9786b2c1a544
STIX ID: report--f6700bd5-c99e-5878-ad2c-9786b2c1a544
Feed Name: SOCRadar Blog
CVE-2025-66376 is a stored XSS vulnerability in Zimbra Collaboration Suite Classic UI that was exploited in the wild by Russian state-aligned actors to steal mail, contacts, credentials, and 2FA/app-password material; affected versions include Zimbra 10.0 (<10.0.18) and 10.1 (<10.1.13). The report provides exploitation timeline, IoCs (domains, IPs, certificate hashes, email/sample hashes), exfiltration URL patterns, detection and hunting guidance (mailbox logs, browser localStorage, network telemetry), and recommended mitigations: immediate patching, suspend Classic UI if needed, reset credentials, revoke app passwords, and search/quarantine malicious messages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
