Back to IntelRead Original Source
Intel Node
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
lowvulnerability2026-07-23T18:36:08+00:00source excerpt
vulnerabilityemail
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.