🔴 Critical | Source: The Hacker News
A Russian state-sponsored espionage group exploited an undisclosed zero-day vulnerability in the Zimbra webmail client to silently harvest emails, contact directories, saved browser passwords, and two-factor authentication recovery codes from targeted Western organisations. The attack was triggered simply by opening a malicious message — no further user interaction was required. The NSA, CISA, and partner agencies have since issued a joint advisory disclosing the campaign.
Security Architect’s Take: Audit your organisation’s use of Zimbra and apply any patches referenced in the NSA/CISA advisory immediately; if running Zimbra on-premises or via a managed service, treat it as actively compromised until patched and reviewed. Critically, review your 2FA strategy — recovery codes stored client-side or in browsers represent a systemic weakness; enforce hardware tokens or passkeys where possible and purge stored recovery codes from browser password managers.
Original advisory: Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes