Russian hackers exploit Zimbra flaw to breach Ukrainian maritime agency
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-66376 | Stored Cross-Site Scripting in Synacor Zimbra Collaboration Suite Classic UI Zimbra Collaboration Suite (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 is vulnerable to stored cross-site scripting through its Classic webmail interface. An attacker sends an HTML e-mail containing a Cascading Style Sheets (CSS) @import directive, and when a recipient opens that message in Classic UI, the injected content executes as script in the victim's browser session. Successful exploitation lets an attacker run arbitrary JavaScript in the Zimbra webmail context, potentially hijacking the session, reading mail, or acting as the user, consistent with the cross-scope impact reflected in the 6.1 CVSS score. Only deployments running the affected ZCS 10/10.1 versions with the Classic UI enabled are exposed; organizations on patched releases or not using Classic UI are not impacted. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-18, confirming exploitation in the wild, and recent reporting describes Zimbra flaws being used by Russian-aligned espionage actors against Western and Ukrainian targets. Do: Upgrade ZCS to 10.0.18 or 10.1.13 (or later) following vendor instructions, as required by CISA's BOD 22-01 KEV guidance; federal agencies and critical infrastructure should prioritize this by the catalog deadline. Until patched, filter or sanitize HTML mail containing CSS @import directives and consider restricting or disabling the Classic UI. Check mailboxes and webmail access logs for suspicious HTML messages and unexplained session activity, which may indicate exploitation. | 6.1 | 20% | KEV |
| largetens of thousands of internet-exposed Zimbra servers (public internet scans typically surface on the order of 50,000+ Zimbra instances), affecting an estimated… |
Full article387 words · extracted from therecord.media · click to collapse
A Russian state-backed hacker group has targeted a Ukrainian government agency using a stealthy phishing campaign that exploits a vulnerability in widely used Zimbra webmail software, according to new research. The operation, attributed with medium confidence to APT28 — also known as Fancy Bear and believed to be linked to Russia’s military intelligence — targeted the State Hydrographic Service of Ukraine which plays a role in maritime navigation and other critical infrastructure services. Researchers at cybersecurity firm Seqrite said the attackers exploited a cross-site scripting flaw, tracked as CVE-2025-66376, allowing them to inject malicious code directly into an email viewed through Zimbra’s browser-based interface. Unlike traditional phishing campaigns, the attack did not rely on malicious attachments or links. Instead, the entire exploit was embedded within the body of a single email that appeared to be a routine internship inquiry written in Ukrainian. “The phishing email has no malicious attachments, no suspicious links, no macros,” the researchers said. “The entire attack chain lives inside the HTML body of a single email.” Once opened in an active Zimbra session, the malicious code executed silently in the victim’s browser, enabling attackers to harvest login credentials, session tokens, backup two-factor authentication codes, browser-stored passwords and up to 90 days of mailbox data. The malicious email was sent in January from what appeared to be a compromised student account.By embedding the payload directly in the email and exploiting a trusted webmail environment, the attackers were able to intercept authenticated sessions without deploying malware or triggering many conventional security defenses, the report said. APT28 has a long history of targeting Ukrainian and Western government entities, defense contractors, and logistics networks in cyber-espionage campaigns. Earlier this month, researchers also linked the group to another operation targeting Ukraine involving previously undocumented malware strains known as BadPaw and MeowMeow. Zimbra webmail has repeatedly been targeted by other Russian-linked hacking groups, including APT29 and Winter Vivern, in espionage campaigns against Eastern European organizations, the researchers said.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russia-hackers-ukraine-zimbra-breach