Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Well, I’m a little less angry about the “Magnificent Ambersons” AI project

Dozens of people march in support of billionaire in San Francisco

From Svedka to Anthropic, brands are boldly leveraging AI in their Super Bowl ads

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Zimbra Zero-day targeted and exploited the Brazilian military through malicious ICS files
Identity

Zimbra Zero-day targeted and exploited the Brazilian military through malicious ICS files

userBy userOctober 6, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 6, 2025Ravi LakshmananEmail Security / Zero Day

Zimbra Zero-Day

The current security vulnerabilities during the patch in Zimbra collaboration were used as zero-days in cyberattacks targeting Brazilian military earlier this year.

The vulnerability tracked as CVE-2025-27915 (CVSS score: 5.4) is a vulnerability in the classic web client cross-site scripting (XSS) that results in insufficient disinfection of HTML content in ICS calendar files.

“When a user views an email message containing a malicious ICS entry, the user’s embedded JavaScript is executed via the Ontoggle event in the tag, according to the NIST National Ulnerability Database (NVD) flaw description.”

DFIR Retainer Service

“This allows an attacker to run arbitrary JavaScript within the victim’s session, potentially leading to rogue actions such as setting email filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim’s account, including email redirection and data extensions.”

The vulnerability was addressed by Zimbra as part of the versions 9.0.0 patch 44, 10.0.13, and 10.1.5 released on January 27, 2025. However, the recommendation does not mention that it was exploited in actual attacks.

However, according to a report published by Strikeready Labs on September 30, 2025, the observed wild activity included an unknown threat actor who caused the Libyan Navy Protocol Bureau to target Brazilian forces using malicious ICS files that exploited the flaws.

The ICS file contained JavaScript code designed to act as a comprehensive data stealer for sucking up credentials, emails, contacts and shared folders to external servers (“ffrk[.]It also searches for emails in a specific folder and adds a malicious Zimbra email filter rule named “Correo” to forward the message to spam_to_junk@proton.me.

CIS Build Kit

To avoid detection, scripts are made to hide certain user interface elements and explode only if it’s been more than 3 days since it last ran.

It is not clear who is behind the attack at the moment, but earlier this year, ESET revealed that a Russian threat actor known as APT28 has exploited XSS vulnerabilities in various webmail solutions from RoundCube, Horde, Mdaemon and Zimbra to gain unauthorized access.

Similar modalities have also been adopted by other hacking groups such as Winter Vivern and UNC1151 (also known as Ghostwriter) to promote qualification theft.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleAfter CL0P exploits it in a data theft attack, Oracle Rushes patches are CVE-2025-61882
Next Article Advanced control strategies for fusion energy devices
user
  • Website

Related Posts

OpenClaw integrates VirusTotal scanning to detect malicious ClawHub skills

February 8, 2026

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

February 7, 2026

The Legal Revolution is Digital: Meet TwinH, Your AI Partner in the Courtroom of the Future

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Well, I’m a little less angry about the “Magnificent Ambersons” AI project

Dozens of people march in support of billionaire in San Francisco

From Svedka to Anthropic, brands are boldly leveraging AI in their Super Bowl ads

OpenClaw integrates VirusTotal scanning to detect malicious ClawHub skills

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.