Russian group read Western mail for months via Zimbra zero-day
State-backed operators harvested 90 days of email, credentials, and 2FA recovery codes through a flaw requiring no user action beyond opening a message.
A Russian state-supported espionage group exploited a previously unknown vulnerability in Zimbra's webmail client to access Western organizational mailboxes over a period of months. The attack required only that a target open a malicious email—no further interaction was necessary to trigger the payload.
The compromise was comprehensive. The malicious code extracted the last 90 days of email correspondence, the organization's complete email directory, browser-saved passwords, and two-factor authentication recovery codes. This combination of access and credential theft enabled sustained, undetected presence within targeted networks.
The NSA, CISA, and partner agencies have now disclosed the campaign. The advisory confirms the flaw was a zero-day at the time of exploitation, meaning Zimbra and the broader security community were unaware of its existence during active abuse. The scope of affected organizations has not been detailed, though the targeting pattern suggests government, defense, and policy-adjacent entities.
- 01Zimbra users face potential months-long exposure to credential theft and email exfiltration
- 02Organizations must audit for compromise indicators and rotate credentials, including 2FA recovery codes
- 03Western government and defense contractors should assume targeting and review access logs
- 04Email-based intelligence collection remains a high-return vector for state actors
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.