A Russian state-sponsored espionage group leveraged a previously unknown vulnerability in Zimbra's webmail client to infiltrate Western mailboxes, extracting sensitive information over several months. The exploit targeted the last 90 days of email, the entire email directory, saved browser passwords, and two-factor recovery codes. Merely opening a malicious message was sufficient to trigger the payload. The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA), along with partner agencies, have since published warnings and advisories1. This zero-day exploit underscores the rapidly diminishing window for patching vulnerabilities, particularly when nation-state actors are involved. The fact that a state-supported group could exploit such a flaw for an extended period highlights the importance of prompt vulnerability assessment and remediation. So what matters to practitioners is that they must immediately assess their exposure to such threats to prevent similar breaches.
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
⚡ High Priority
Why This Matters
Zero-day activity targeting NSA means patching windows are already closing — assess your exposure immediately.
References
- The Hacker News. (2026, July 23). Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes. The Hacker News. https://thehackernews.com/2026/07/russian-espionage-group-exploited.html
Original Source
The Hacker News
Read original →