Rosjanie wykradają e-maile ciekawym atakiem XSS. Agencja Wywiadu i SKW ostrzegają!
Ten atak jest dość przerażający, bo ofiara w ogóle nie musi klikać ani w link, ani w złośliwy załącznik. Wystarczy, że otworzy e-maila…
Sprytny i potężny XSS wykradał e-maileJak ostrzega wiele służb specjalnych z różnych krajów, w tym nasza Agencja Wywiadu razem z SKW, rosyjska grupa TA488, znana też jako (Void Blizzard/Laundry Bear) w ciekawy sposób atakowała użytkowników webowego interfejsu poczty e-mail Zimbra. Ofiarom wysyłano e-maila w HTML-u, w którym znajdował się payload XSS, czyli złośliwy kod JavaScript:
Payload zdekodowany przez Proofpoint
Atakujący rozbijali niebezpieczne znaczniki fragmentami CSS @import i komentarzami, czego filtry Zimbry nie wykrywały, ale przeglądarka bez problemu składała w całość i wykonywała ukryte, złośliwe instrukcje. Kod atakujących miał dostęp do danych dostępnych dla zalogowanego użytkownika, a że nie zostawiał żadnego wyraźnego śladu w systemie ofiary w porównaniu do klasycznego malware, to EDR-y i antywirusy miały trudność z reagowaniem na ten atak.
Rosjanie próbowali wykradać:
wiadomości z ostatnich 90 dni,
książkę adresową organizacji,
hasła podpowiadane przez przeglądarkę,
awaryjne kody 2FA i token CSRF,
Tak, to wszystko jest możliwe i całkiem łatwe, dzięki zwykłemu JavaScriptowi. Jeśli chcesz się nauczyć, jak dziury typu XSS wykrywać i łatać w swoich aplikacjach, aby uniemożliwiać takie ataki (ale także jak tego typu podatności uzbroić, żeby omijać filtry i robić nawet bardziej zaawansowane eksfiltracje danych) to przypominamy, że tylko do poniedziałku nasz Internetowy Kurs Ataków XSS można kupić aż o 30% taniej z kodem XSS30.
Dostęp do 30 lekcji, które krok po kroku prowadzą przez ten [...]
#AgencjaWywiadu #Ataki #KursXSS #Rosja #SKW #Webapliacje #XSS #Zimbra
https://niebezpiecznik.pl/post/rosjanie-wykradaja-e-maile-ciekawym-atakiem-xss-agencja-wywiadu-i-skw-ostrzegaja/
About This Hashtag
#zimbra
16 posts
Last used Aug 06
#zimbra
16 posts· Last used Aug 06
Replying to @security_crawler_carl@infosec.exchange
Reward: Congratulations! You've received a Loot Box containing your own sent folder, read receipts, and attachments. Non-transferable. Non-refundable. Already transferred.
#Cybersecurity #RussianHackers #Zimbra #EmailSecurity #ZeroDay #NoSocialEngineeringNeeded (3/3)
Russian hackers exploit #Zimbra zero-click flaw for #email theft
https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/
#cybersecurity
Replying to @security_crawler_carl@infosec.exchange
CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.
Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.
Reward: You've received a hollow Authenticator Token — pre-drained.
#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)
🤖 Russian state-sponsored group Laundry Bear exploits Zimbra zero-click 0-day to steal emails, contacts, and 2FA recovery codes from US/Ukraine targets. Opening or previewing the message is enough to trigger the exploit. CISA, NSA & FBI issued a joint advisory.
🔗 https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/
#0day #CyberSec #Zimbra #CISA #Russia
🤖 CISA warns Russian APT group Laundry Bear (Void Blizzard) is exploiting a zero-click Zimbra Collaboration vulnerability in active attacks. The flaw, combined with phishing, allows email theft from unpatched servers.
🔗 https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/
#CVE #Zimbra #CyberSec #APT #EmailSecurity
New advisory.
CISA: Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a #CISA #infosec #Zimbra #phishing
New.
Cisco: Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/ @TalosSecurity@mstdn.social
Group-IB (co-written by a marketer): Ransomware in 2026: Same Business, New Rules https://www.group-ib.com/blog/ransomware-2026-rules/
Warning: Recorded Future sells everything and the kitchen sink to third parties, including Google. No consent, no options.
Recorded Future: TAG-195 Upgrades MaaS Ecosystem with Modular Tools https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
Microsoft: Email threat landscape: Q2 2026 trends and insights https://www.microsoft.com/en-us/security/blog/2026/07/23/email-threat-landscape-q2-2026-trends-and-insights/
Proofpoint; TA488 Targets Zimbra Mailservers with Half-Click Exploits https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
---
Rapid7: What Happened Between OpenAI and Hugging Face? https://www.rapid7.com/blog/post/ai-openai-hugging-face-what-happened/ @Rapid7Official@infosec.exchange
Picus:
"OpenAI was doing something reasonable and responsible. It was measuring how good its frontier models are at offensive cyber operations, so it could understand the risk."
Picus: The Day an AI Cheated on Its Exam by Hacking Another Company https://www.picussecurity.com/resource/blog/the-day-an-ai-cheated-on-its-exam-by-hacking-another-company
---
Posted yesterday:
Huntress: Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat @huntress@infosec.exchange
Fortinet: Inside a TrickBot Variant Using DNS Tunneling for C2 https://www.fortinet.com/blog/threat-research/inside-a-trickbot-variant-using-dns-tunneling-for-c2 @fortinet@infosec.exchange #infosec #threatresearch #ransomware #Windows #Microsoft #Claude #phishing #OpenAI #Zimbra
Zimbra must be very proud of this record.
"Kremlin cyber goons have been breaking into government and commercial networks for at least a year by exploiting a Zimbra bug with a novel twist. "
The Register: Year-long Russian attacks infect users as soon as they look at an email https://www.theregister.com/patches/2026/07/23/year-long-russian-attacks-infect-users-as-soon-as-they-look-at-an-email/5277358 @theregister@geeknews.chat #malware #infosec #phishing #Zimbra
Proofpoint ties TA488 and TA458 to half-click exploits and webmail zero-days that steal email from Ukrainian, NATO and US government mailservers.
#HalfClickExploit #Zimbra #Roundcube #APT #Proofpoint
https://securityonline.info/half-click-exploits-webmail/?utm_source=mastodon&utm_medium=jetpack_social
#Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug
https://securityaffairs.com/195752/security/zimbra-10-1-20-patches-multiple-security-issues-including-a-critical-command-injection-bug.html
#securityaffairs #hacking
Zimbra 10.1.20 fixes multiple Zimbra vulnerabilities, including an SNMP command injection flaw and several XSS bugs. Admins should upgrade now.
#Zimbra #Zimbra10120 #Vulnerability #XSS #SNMP #Cybersecurity #PatchNow
https://securityonline.info/zimbra-10-1-20-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
Zimbra Collaboration Suite Classic Web Client <10.1.19 has a CRITICAL stored XSS vulnerability — malicious code can execute when crafted emails are opened, risking mailbox and session compromise. Patch to 10.1.19 now. https://radar.offseq.com/threat/zimbra-patches-critical-code-execution-vulnerabili-2aeadfb7a8c266eb #OffSeq #Zimbra #AppSec #XSS
🤖 Critical Zimbra flaw: stored XSS in Classic Web Client enables arbitrary code execution via crafted emails. No CVE yet. Patch available — apply urgently.
🔗 https://thehackernews.com/2026/07/critical-zimbra-flaw-could-let-crafted_0483473395.html
#Zimbra #XSS #CyberSec
Update Now: Critical #Zimbra Classic Web Client Flaw Could Expose Mailboxes
https://securityaffairs.com/195130/hacking/update-now-critical-zimbra-classic-web-client-flaw-could-expose-mailboxes.html
#securityaffairs #hacking
You've seen all posts