Back to the feed

~/article/russian-espionage-group-exploited-zimbra-zero-day-to-steal-mail-and-2fa-c5urtz
criticalSource: The Hacker News

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The NSA, CISA and partner agencies published

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/russian-espionage-group-exploited-zimbra-zero-day-to-steal-mail-and-2fa-c5urtz