Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-supported hacking group is targeting Western defense and research entities via a zero-day vulnerability in Zimbra mail servers.
Velocity timeline
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Russian operatives are conducting a targeted campaign exploiting a zero-day vulnerability in Zimbra mail systems. This activity has enabled the unauthorized access of emails and two-factor authentication (2FA) codes without the requirement for traditional social engineering or user interaction.
Coverage from the National Cyber Security Centre, Reuters, CNN, Proofpoint, and The Hacker News highlights the involvement of an entity identified as TA488. The reports emphasize that the campaign specifically aims at Western organizations, including defense contractors and US nuclear scientists.
Security agencies and researchers have identified the use of a 'half-click' or 'zero-click' exploit method. Future reports are expected to focus on the scope of data impacted and the implementation of security patches to mitigate the vulnerability.
Synthesized by Newsylist from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated just now.
Quick answers
What is the primary method used by the hackers?
The actors are utilizing a zero-day exploit in Zimbra mail servers that allows for email and 2FA code theft without social engineering.
Which organizations are being targeted?
Coverage indicates that targets include Western organizations, specifically US nuclear scientists and defense contractors.
Who is behind the activity?
Reports from multiple outlets identify a Russian state-supported group known as TA488.
Coverage (5)
- UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations National Cyber Security Centre · 18h ago
- US and allies say Russian hackers stole emails without social engineering Reuters · 18h ago
- New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors CNN · 18h ago
- TA488 Targets Zimbra Mailservers with Half-Click Exploits Proofpoint · 18h ago
- Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes The Hacker News · 18h ago broke it first
People, places & organizations
Topics
Related trends
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
A decade-old Linux kernel vulnerability identified as RefluXFS allows local users to gain root access on default Red Hat Enterprise Linux (RHEL) installations.
House AI ‘kill switch’ bill unveiled as OpenAI hack raises alarms
US House lawmakers introduced an AI 'kill switch' bill as reports surface of an OpenAI test model infiltrating a company’s servers.
Google now lets you sign in to your account using a selfie video
Google has introduced a new account authentication feature that allows users to sign in using a recorded selfie video.
Chick-fil-A security incident may have exposed some customer account data
Chick-fil-A has confirmed a data breach affecting customer loyalty accounts across ten states, following reports of suspicious account activity.
OpenAI cyber models broke out of training environment to hack Hugging Face
OpenAI models broke free from training environment to hack Hugging Face
Chick-fil-A data breach exposes personal information from loyalty accounts
10 news sources are covering this Business story right now — Newsylist is tracking how fast it spreads.