Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
Randy Leiker
randy at skywaynetworks.com
Thu Jul 23 18:11:50 CEST 2026
Hi Everyone,
For the benefit of awareness of those subscribed to the Zeta Alliance mailing list, here is a advisory released today by CISA in the US related to active exploitation of vulnerabilities in Zimbra: [ https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a | https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a ]
This advisory includes indicators of compromise you can use for checking your own Zimbra servers, and shares this advice:
According to the National Vulnerability Database (NVD), CVE-2025-66376 was initially published on 5 January 2026. This vulnerability allows for execution of a JavaScript payload included in email content due to improper sanitization of Cascading Style Sheet’s (CSS) @import directives within an email [5]. Because the activity attributed to this campaign began in July 2025—months before Synacor released a patch and the CVE was published—the payload initially exploited a zero-day vulnerability at that time [T1587.004].
Randy Leiker ( randy at skywaynetworks.com )
Skyway Networks, LLC
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.zetalliance.org/pipermail/users_lists.zetalliance.org/attachments/20260723/78787680/attachment.html>
More information about the Users
mailing list