Zimbra zero-day: opening a malicious email could expose mail and 2FA codes

Colleagues, I would like to draw attention to an important cybersecurity development.
A zero-day in Zimbra Classic UI reportedly required nothing more than a user opening a malicious email.
According to researchers, the attack could:
• read mail from the past 90 days;
• access the address book and browser-saved passwords;
• steal 2FA recovery codes;
• create access via app-specific passwords.
Why it matters: a patch closes the vulnerability, but it does not undo data already stolen. Check versions, review account audits, reset passwords and sessions, and update scratch codes.
Have you already checked Zimbra in your environment?
#cybersecurity #Zimbra #ZeroDay #EmailSecurity


Latest comments
No comments yet.