Roundcube under attack: phishing via email hits universities

Colleagues, I’d like to draw your attention to a cybersecurity incident.
According to a Proofpoint report, a China-linked suspected group is targeting universities in the US and Canada via Roundcube.
The attack chain is as follows:
- it exploits already patched vulnerabilities, including CVE-2024-42009;
- it steals credentials, 2FA tokens, and cookies;
- it then establishes persistence via a web shell or VShell.
What is especially concerning is that the target selection is deliberate: the focus is on departments holding data of value to government interests and research.
Why this matters: today, an email server is as critical a perimeter as a VPN. Patches, DMARC, and inbound email controls are mandatory.
How do you protect your company’s email infrastructure?
#cybersecurity #Roundcube #phishing #emailsecurity

