Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
러시아 정보 그룹이 Zimbra의 제로데이 취약점을 이용해 이메일과 2FA 코드를 탈취했다.
러시아의 국가 지원 정보 그룹이 Zimbra의 웹메일 클라이언트에서 발견된 제로데이 취약점을 이용해 서방의 이메일을 수개월간 엿보았다. 이 공격은 사용자가 메시지를 열기만 해도 시작되며, 최근 90일간의 이메일, 이메일 디렉토리, 브라우저에 저장된 비밀번호 및 이중 인증 복구 코드를 탈취한다. NSA, CISA 및 파트너 기관이 이 사실을 발표했다.
Russian espionage group exploited Zimbra zero-day to steal emails and 2FA codes.
A Russian state-supported espionage group exploited an unknown flaw in Zimbra's webmail client to monitor Western inboxes for months. The attack could be initiated simply by opening a message, allowing the extraction of the last 90 days of emails, the organization's email directory, passwords stored in browsers, and recovery codes for two-factor authentication. The NSA, CISA, and partner agencies have published information on this vulnerability.