As cited
Copy frozen at (site build).
vulnerabilities
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned threat group is exploiting patched critical vulnerabilities in Roundcube webmail software at U.S. and Canadian university physics and engineering departments to steal credentials. The campaign leverages flaws including CVE-2024-42009, a critical vulnerability with a CVSS score of 9.3 in the open-source email solution.
Why it matters: Universities and organizations running unpatched Roundcube instances need to patch immediately; academic researchers and their email accounts are actively targeted for credential theft by state-aligned attackers.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
A suspected China-aligned threat group is exploiting patched critical vulnerabilities in Roundcube webmail software at U.S. and Canadian university physics and engineering departments to steal credentials. The campaign leverages flaws including CVE-2024-42009, a critical vulnerability with a CVSS score of 9.3 in the open-source email solution.
Why it matters: Universities and organizations running unpatched Roundcube instances need to patch immediately; academic researchers and their email accounts are actively targeted for credential theft by state-aligned attackers.
- Source published
- First seen by Cybersecurity Tracker