Chinese Hackers Target University Roundcube Servers
đ High |Â Source: The Register â Security Suspected Chinese state-sponsored threat actors have been observed compromising Roundcube webmail servers at universities, exploiting vulnerabilities to conduct espionage. Proofpoint researchers estimate the campaign targeted a few dozen institutions, suggesting a focused, intelligence-gathering operation rather than opportunistic mass exploitation. The incident highlights the continued targeting of academic institutions, which often hold sensitive research and government-adjacent data. Security Architectâs Take: If your organisation runs Roundcube, patch immediately and audit server logs for indicators of compromise, particularly any unauthorised access to mailboxes or configuration files. More broadly, consider migrating legacy open-source webmail deployments to hardened, actively maintained platforms and enforce MFA across all email access points. ...