ATLAS · LIVE
ATLAS INDEX
Δ 24H
ACTIVE SOURCES20
HOTSPOTS20
TIME23:08:28 UTC
← All briefs
CRITICALCyber IntelligenceFriday, July 24, 2026

Russian group read Western mail for months via Zimbra zero-day

State-backed operators harvested 90 days of email, credentials, and 2FA recovery codes through a flaw requiring no user action beyond opening a message.

A Russian state-supported espionage group exploited a previously unknown vulnerability in Zimbra's webmail client to access Western organizational mailboxes over a period of months. The attack required only that a target open a malicious email—no further interaction was necessary to trigger the payload.

The compromise was comprehensive. The malicious code extracted the last 90 days of email correspondence, the organization's complete email directory, browser-saved passwords, and two-factor authentication recovery codes. This combination of access and credential theft enabled sustained, undetected presence within targeted networks.

The NSA, CISA, and partner agencies have now disclosed the campaign. The advisory confirms the flaw was a zero-day at the time of exploitation, meaning Zimbra and the broader security community were unaware of its existence during active abuse. The scope of affected organizations has not been detailed, though the targeting pattern suggests government, defense, and policy-adjacent entities.

The rest of this brief is inside the platform

Continue reading. Free.

A free Atlas account unlocks the full briefing, the co-analyst, daily delivery to your inbox, and a sector-personalised feed.

Full brief
Implications, sources, methodology
Co-Analyst
Ask follow-ups on every brief
Sector feed
Briefs filtered to what matters to you
Implications
  • 01Zimbra users face potential months-long exposure to credential theft and email exfiltration
  • 02Organizations must audit for compromise indicators and rotate credentials, including 2FA recovery codes
  • 03Western government and defense contractors should assume targeting and review access logs
  • 04Email-based intelligence collection remains a high-return vector for state actors
Source
The Hacker News
https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
Brief is editorial commentary by Atlas Intelligence based on the cited public reporting. Atlas does not reproduce source text. Verify primary source before action.
#zimbra#zero-day#russian espionage#credential theft#2fa bypass#webmail
Related Briefs