Zero-Day Exploits: European Governments and Russian Organizations Targeted in Roundcube Webmail Hacks

1 min read
Source: BleepingComputer
Zero-Day Exploits: European Governments and Russian Organizations Targeted in Roundcube Webmail Hacks
Photo: BleepingComputer
TL;DR Summary

The Winter Vivern Russian hacking group has been exploiting a zero-day vulnerability in Roundcube Webmail to target European government entities and think tanks since October 11. The vulnerability allowed the group to remotely inject arbitrary JavaScript code into Roundcube email servers, enabling them to harvest and steal emails. The Roundcube development team released security updates to fix the vulnerability after it was reported by ESET researchers. Winter Vivern has previously targeted government organizations using known vulnerabilities in Roundcube and Zimbra email servers. The group's persistence and regular phishing campaigns pose a significant threat to European governments.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

78%

43296 words

Want the full story? Read the original article

Read on BleepingComputer