CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Russian Global Webmail Espionage

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3124

As cited

Copy frozen at (site build).

threat intel

Russian Global Webmail Espionage

Unit 42 identifies a Russian-linked cyberespionage campaign targeting Zimbra webmail servers through JavaScript injection attacks designed to capture user credentials. The threat actors inject malicious code into compromised Zimbra instances to harvest login credentials from victims.

Why it matters: Organizations operating Zimbra webmail infrastructure are at direct risk of credential theft and account compromise; security teams should immediately audit Zimbra instances for unauthorized code modifications and monitor for anomalous authentication patterns.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary