Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Western government and commercial organizations
Incident: Exploitation of a Zimbra zero-day vulnerability to steal emails and security credentials.
Impact: Complete compromise of user mailboxes, theft of 2FA recovery codes, and leakage of organizational address books.
Attacker: TA488 (associated with APT28/Void Blizzard)
Analysis: The campaign utilizes CVE-2025-66376, a stored XSS flaw in Zimbra’s Classic UI, to execute JavaScript simply by viewing a malicious email. By splitting HTML tags with CSS @import directives, the ‘ZimReaper’ payload evades security filters to exfiltrate passwords, 2FA codes, and the Global Address List. The attackers targeted high-value Western government and commercial entities for strategic intelligence gathering.
Recommendations: Update Zimbra Collaboration to version 10.0.18 or 10.1.13 immediately.; Force a password reset and rotate 2FA recovery codes for all users, as patches do not revoke stolen credentials.; Audit DNS logs for unusual outbound queries and review mail access logs for unauthorized activity.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source