Vulnerabilità ed exploit
Zimbra resta leggibile anche dopo la patch Il punto critico non è un nuovo bug, ma il fatto che la stessa XSS continua a funzionare dopo la correzione. In Zimbra Classic UI basta aprire un messaggio per far partire lo script malevolo; la lettura della casella diventa quindi il punto di compromissione, non un semplice segnale di phishing.
Le agenzie statunitensi e partner europei dicono che Laundry Bear usa CVE-2025-66376 dal luglio 2025 e che il traffico colpisce governo, difesa, education, energia, legale, media e tecnologia. Il gruppo punta a raccogliere email recenti, directory, token MFA e nuovi app passcode, quindi una casella già vista durante la finestra di esposizione va trattata come potenzialmente saccheggiata. Il caso Notepad++ con UAC-0099 è separato e non deve rallentare la triage su Zimbra.
13 fonti · 24 lug
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97º percentile).
Data di correzione federale CISA 1 apr · data superata
Cronologia Fonti 24 lug Help Net Security
Russian hackers exploit unpatched Zimbra servers to steal emails - Help Net Security
Laundry Bear exploited a Zimbra Collaboration Suite vulnerability in phishing attacks targeting governments and critical sectors worldwide.
originale 24 lug The Hacker News
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every three minutes on Windows.
originale 24 lug Risky Biz News
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
A Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and [Read More
originale Part of the PlainSec briefing for 2026-07-23
Every edition of this story: Zimbra resta leggibile anche dopo la patch
Altro da oggi
Vulnerabilità ed exploit
Zimbra resta leggibile anche dopo la patch Il punto critico non è un nuovo bug, ma il fatto che la stessa XSS continua a funzionare dopo la correzione. In Zimbra Classic UI basta aprire un messaggio per far partire lo script malevolo; la lettura della casella diventa quindi il punto di compromissione, non un semplice segnale di phishing.
Le agenzie statunitensi e partner europei dicono che Laundry Bear usa CVE-2025-66376 dal luglio 2025 e che il traffico colpisce governo, difesa, education, energia, legale, media e tecnologia. Il gruppo punta a raccogliere email recenti, directory, token MFA e nuovi app passcode, quindi una casella già vista durante la finestra di esposizione va trattata come potenzialmente saccheggiata. Il caso Notepad++ con UAC-0099 è separato e non deve rallentare la triage su Zimbra.
13 fonti · 24 lug
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style… EPSS 20% (97º percentile).
Data di correzione federale CISA 1 apr · data superata
Cronologia Fonti 24 lug Help Net Security
Russian hackers exploit unpatched Zimbra servers to steal emails - Help Net Security
Laundry Bear exploited a Zimbra Collaboration Suite vulnerability in phishing attacks targeting governments and critical sectors worldwide.
originale 24 lug The Hacker News
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
CERT-UA links UAC-0099 to a fake Notepad++ plugin that deploys BURNYBEAR and MATCHBOIL.V2, with persistence running every three minutes on Windows.
originale 24 lug Risky Biz News
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
A Russian hacking campaign targets Zimbra servers, the US accuses Moonshot AI of distillation attacks, Iran targets more PLC vendors, and [Read More
originale Part of the PlainSec briefing for 2026-07-23
Every edition of this story: Zimbra resta leggibile anche dopo la patch
Altro da oggi