DAPSSADAPSSA

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

By DAPSSA AI Desk | 2026-07-24T05:35:13.777Z
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

Overview

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it. The NSA, CISA and partner agencies published

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/07/russian-espionage-group-exploited.html

Join the Discussion