A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal emails, passwords, and two-factor authentication recovery codes…
Zimbra has released security updates addressing nine vulnerabilities in Zimbra 10.1.20, including a critical command injection flaw in the Simple Network Management…
Classic Web Clientcommand injectionCVE-2026-50055email security
ZeroBAC is an email security company that discovered and analyzed the Forg365 PhaaS operation, providing detailed technical analysis of its capabilities.
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
Zimbra has disclosed a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could allow attackers to execute arbitrary…
arbitrary code executionClassic Web Clientcross-site scriptingCVE-2023-37580
A recent EvilTokens campaign is exploiting a new 'ghost phishing' technique that hides malicious content until it decrypts inside the victim's browser,…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…