Zimbra Flaw Exploited Before Disclosure
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.
6 results for “zimbra”
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.
Microsoft says attackers chained a patched Zimbra command-injection flaw into web shells, credential theft and cloud exfiltration.
Threat actors compromised over 270 Zimbra instances in ongoing RCE attacks, prompting CISA to order urgent patching.
A sophisticated campaign by the threat group Laundry Bear has bypassed user interaction to harvest sensitive government data.
A severe vulnerability in the Classic Web Client requires immediate patching to prevent unauthorized code execution via email.
A persistent cross-site scripting flaw in Zimbra's classic client underscores the relentless exploitation of enterprise email platforms.