As cited
Copy frozen at (site build).
vulnerabilities
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
Western cybersecurity and intelligence agencies issued a joint warning on Thursday about a Russian hacking campaign targeting Zimbra email servers since at least July 2024. The campaign exploited CVE-2025-66376, a stored XSS vulnerability in the Zimbra webmail client's CSS @import feature, which was patched in November but remains under active attack. The malicious code loads a tool called Ulej to harvest credentials, session tokens, backup two-factor authentication codes, saved passwords, and up to 90 days of email contents.
Why it matters: Organizations running Zimbra email servers are under active targeting by a Russian threat actor; apply the November patch immediately if not already deployed, and hunt for indicators of the Ulej tool in webmail logs.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
Western cybersecurity and intelligence agencies issued a joint warning about a Russian hacking campaign targeting Zimbra email servers since at least July 2025. The attacks exploit CVE-2025-66376, a stored cross-site scripting vulnerability in the webmail client's CSS @import feature, patched in November 2025. The vulnerability enables attackers to inject malicious code that deploys a credential-harvesting tool called Ulej to steal login credentials, session tokens, two-factor authentication backup codes, saved passwords, and up to 90 days of email content.
Why it matters: Organizations running Zimbra email servers face credential theft and email compromise if they have not patched CVE-2025-66376; verify the November 2025 patch is deployed and review mailbox access logs for suspicious activity.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers
Western cybersecurity and intelligence agencies issued a joint warning about a Russian hacking campaign targeting Zimbra email servers since at least July 2025. The attacks exploit CVE-2025-66376, a stored cross-site scripting vulnerability in the webmail client's CSS @import feature, patched in November 2025. The vulnerability enables attackers to inject malicious code that deploys a credential-harvesting tool called Ulej to steal login credentials, session tokens, two-factor authentication backup codes, saved passwords, and up to 90 days of email content.
Why it matters: Organizations running Zimbra email servers face credential theft and email compromise if they have not patched CVE-2025-66376; verify the November 2025 patch is deployed and review mailbox access logs for suspicious activity.
- Source published
- First seen by Cybersecurity Tracker