Russian hackers turn to AI as old tactics fail, Ukrainian CERT says
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-43770 | Persistent Cross-Site Scripting in Roundcube Webmail (Exploited in the Wild) Roundcube Webmail versions before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 contain a persistent cross-site scripting (XSS) flaw (CWE-79) caused by how program/lib/Roundcube/rcube_string_replacer.php converts plain text into clickable links. An attacker sends a text/plain email containing crafted links; when the recipient views the message, the crafted link text is turned into HTML that runs attacker-controlled script, which persists and executes in the victim's webmail session. Successful exploitation lets the attacker execute JavaScript with the victim's session, enabling mailbox access, theft of session credentials, and actions performed as the user (CVSS 6.1, scope-changed with limited confidentiality and integrity impact). Anyone running an affected Roundcube instance is exposed, including the roundcube package shipped with Debian Linux. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-02-12, and EPSS assigns a 58.5% probability of exploitation within 30 days (99th percentile). Do: Upgrade Roundcube to 1.4.14, 1.5.4, or 1.6.3 (or later, per branch), or install the updated roundcube package on Debian. Because the bug is in CISA's KEV catalog, U.S. federal agencies must apply the vendor fix by the catalog due date, and other defenders should prioritize patching internet-facing webmail servers. Review webmail access logs for suspicious message views or account activity, and consider forcing session re-authentication for accounts that opened crafted plain-text messages. | 6.1 | 58% | KEV |
| massplausibly millions of users across tens of thousands of internet-exposed Roundcube instances (estimate) |
Full article517 words · extracted from therecord.media · click to collapse
Russian hackers are increasingly using artificial intelligence and adopting new tactics in cyberattacks against Ukraine as Kyiv’s defenses grow stronger, Ukrainian government researchers said in a new report. Since Russia’s invasion in 2022, cyberattacks on Ukraine have continued to rise, surpassing 3,000 cases in the first half of this year — about 20 percent more than the same period last year. At the same time, the number of high-impact incidents has declined as Ukraine’s defenses improve. That progress has forced Russian hackers to abandon outdated tactics, automate more of their operations and increasingly experiment with AI-generated malware, according to Ukraine’s computer emergency response team, CERT-UA. In a report released Wednesday, the agency warned that attackers are now using AI not only to write phishing messages but also to generate malicious code itself. Researchers believe AI tools were used to create PowerShell scripts in malware known as Wrecksteel, attributed to the cyberespionage group UAC-0219. “The use of artificial intelligence in cyberattacks has reached a new level,” CERT-UA said. “We have investigated several viruses showing clear signs of being generated with AI, and attackers will certainly not stop there.” Read more: Ukraine warns of growing AI use in Russian cyber-espionage operations Russian hackers are also adapting to faster infrastructure takedowns, researchers said. Improvements in Ukraine’s detection systems and closer cooperation with international cloud providers have pushed attackers toward shorter, more transient campaigns. Instead of maintaining persistence within networks, hackers increasingly deploy data-stealing tools that grab what they can and disappear — a shift CERT-UA described as the “Steal & Go” model. As phishing becomes less effective against better-trained Ukrainian users, Russian hackers are increasingly turning to so-called zero-click vulnerabilities — software flaws that allow infections without any user interaction. CERT-UA noted a surge in the use of such vulnerabilities in early 2025, including renewed exploitation of a known flaw in the open-source email platform Roundcube (CVE-2023-43770). The vulnerability allows attackers to execute malicious code when an email is merely viewed in the inbox — no clicks required. Moscow also continues to synchronize cyber operations with missile and drone strikes to amplify their disruptive effect, the report said. CERT-UA cited the Sandworm hacking unit, linked to Russia’s military intelligence, as one of the groups coordinating such hybrid attacks. CERT-UA said that Russia’s evolving tactics and techniques, including new methods of spreading malware, have been partly successful. Still, Ukraine’s defenders said they have managed to keep up, detecting and neutralizing roughly as many infections as they find. “After more than three years of full-scale war, the enemy has still not achieved the goals of its so-called special military operation,” researchers said. “Every day it increases the number of its attacks — both drones and missiles, and cyberattacks.”
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russian-hackers-turn-to-ai-ukraine-cert