Hackers Exploiting Zimbra 0-day to Attack

Hackers Exploiting Zimbra 0-day to Attack

Zimbra Collaboration is an open-source solution software suite with an email server and web client for collaboration.  Over 5,000 companies and public sector users, along with hundreds of millions of end-users in more than 140 countries, utilize this solution. Google...
Phishing campaign steals accounts for Zimbra email servers worlwide

Phishing campaign steals accounts for Zimbra email servers worlwide

An ongoing phishing campaign has been underway since at least April 2023 that attempts to steal credentials for Zimbra Collaboration email servers worldwide. According to a report by ESET, phishing emails are sent to organizations worldwide, with no specific focus on...
Phishing Campaign Targets Zimbra Users

Phishing Campaign Targets Zimbra Users

A new phishing campaign is targeting small and medium-sized businesses and government agencies in several countries that use the Zimbra Collaboration platform, aiming to gather credentials for use in potential further operations. The campaign has been ongoing since at least...
Zimbra credentials targeted in global phishing campaign

Zimbra credentials targeted in global phishing campaign

A long-running phishing campaign targeting small- to medium-size businesses and government entities is successfully snaring account credentials belonging to users of the Zimbra Collaboration software platform.The campaign, carried out by an unidentified threat group, has been active since at least...
Phishing Attack Targets Hundreds of Zimbra Customers in 4 Continents

Phishing Attack Targets Hundreds of Zimbra Customers in 4 Continents

Despite its simplicity, a phishing campaign targeting customers of the Zimbra Collaboration software suite has spread to hundreds of organizations in over a dozen countries.Zimbra is a collaborative software suite, which includes an email server and Web client. It is...
Users of collaboration tool Zimbra have their accounts stolen

Users of collaboration tool Zimbra have their accounts stolen

A new phishing campaign targeting users of the Zimbra Collaboration email servers has been spotted, and researchers are saying it’s quite successful. Zimbra Collaboration is a online collaborative suite that comes with an email server and a web client. According to researchers...
Unpacking the Zimbra Cross-Site Scripting Vulnerability (CVE-2023-37580)

Unpacking the Zimbra Cross-Site Scripting Vulnerability (CVE-2023-37580)

Insights and Protections On November 16, 2023, a significant security concern was published by Google’s Threat Analysis Group (TAG). They revealed an alarming vulnerability in Zimbra Collaboration, a widely-used email hosting tool for organizations. This vulnerability, designated with an identifier,...
APTs Swarm Zimbra Zero-Day to Steal Government Info Worldwide

APTs Swarm Zimbra Zero-Day to Steal Government Info Worldwide

At least four separate cyberattack groups have used a former zero-day security vulnerability in the Zimbra Collaboration Suite (ZCS) to steal email data, user credentials, and authentication tokens from government organizations globally.ZCS is an email server, calendaring, and chat and...
Google Says 4 Attack Campaigns Exploited Zimbra Zero-Day

Google Says 4 Attack Campaigns Exploited Zimbra Zero-Day

Governance & Risk Management , Patch Management Zimbra Patched the Cross-Site Scripting Vulnerability on July 25 Prajeet Nair (@prajeetspeaks) • November 16, 2023     Google says four different threat actors exploited a flaw in the Zimbra Collaboration email server....
Loading posts...

All posts loaded

No more posts