Russian hackers exploit Zimbra zero-click flaw for email theft
Summary
Russian state-sponsored hackers are exploiting a zero-click vulnerability in Zimbra Collaboration email servers to steal emails. CISA has issued a warning about this campaign, which combines phishing attacks with the exploitation of a now-patched flaw.
IFF Assessment
FOE
This article details an active exploitation of a vulnerability by a state-sponsored threat actor to steal sensitive data, representing a direct threat to organizations.
Defender Context
Organizations using Zimbra should ensure their systems are fully patched against known vulnerabilities, even older ones, as threat actors continue to leverage them for targeted attacks. Defenders should also maintain vigilance against sophisticated phishing attempts that may be precursors to or combined with exploit execution.