Zimbra Classic UI: Email Collaboration Software Interface
The classic user interface of Zimbra collaboration software, exploited via CVE-2025-66376 by Laundry Bear to deploy ZimReaper.
The classic user interface of Zimbra collaboration software, exploited via CVE-2025-66376 by Laundry Bear to deploy ZimReaper.
Zimbra is an email and collaboration platform targeted by Laundry Bear using CVE-2025-66376 to deliver ZimReaper malware.
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
A JavaScript payload deployed via half-click exploits targeting Zimbra, capable of harvesting 90 days of victim email and other data, used by…
A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal emails, passwords, and two-factor authentication recovery codes…
A cross-site scripting (XSS) flaw in Zimbra's Classic UI exploited by Laundry Bear to deploy the ZimReaper payload, harvesting email data from…
Zimbra has released security updates addressing nine vulnerabilities in Zimbra 10.1.20, including a critical command injection flaw in the Simple Network Management…
A vulnerability in Zimbra that allows authenticated users to bypass mail forwarding restrictions and exfiltrate email. Discovered by Rapid7 researcher Jonah Burgess.
Zimbra 10.1.20 is the latest version that patches nine security vulnerabilities including critical SNMP command injection and multiple XSS flaws.
This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…