logo

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

ID: f7b9f5cd-dc14-5fb1-9771-3225b180875f

STIX ID: report--f7b9f5cd-dc14-5fb1-9771-3225b180875f

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: [email protected] (The Hacker News)

...
...

A Russian state-linked espionage group exploited a stored XSS in Zimbra Classic Web Client (CVE-2025-66376) using a view-only, tag-splitting HTML email that executed a JavaScript payload (ZimReaper) to steal CSRF tokens, autofilled passwords, 2FA scratch codes, enumerate the Global Address List, and exfiltrate 90 days of mail; vendors and US agencies released advisories, mitigations, and IoCs while recommending patching, credential resets, session invalidation, and account reviews.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.