Google's Threat Analysis Group (TAG) has discovered that threat actors exploited a zero-day vulnerability in Zimbra Collaboration email server to steal sensitive data from government systems in multiple countries. Hackers leveraged a medium-severity security issue now identified as CVE-2023-37580 since June 29, nearly a month before the vendor addressed it in version 8.8.15 Patch 41of the software on July 25. The flaw is an XSS (cross-site scripting) issue present in the Zimbra Classic Web Client. According to Google's threat analysts, the threat actors exploited the vulnerability on government systems in Greece, Moldova, Tunisia, Vietnam, and Pakistan to steal email data, user credentials, and authentication tokens, perform email forwarding, and lead victims to phishing pages. Google observed four distinct threat actors using the vulnerability that was unknown at the time of exploitation in late June 2023 against a government organization in Greece. The attackers sent emails with a malicious URL that allowed email data exfiltration and enabled auto-forwarding to an attacker-controlled address. Zimbra pushed an emergency hotfix on GitHub after Google analysts alerted the company of the observed compromises. The second campaign was conducted on July 11 by a threat actor tracked as "Winter Vivern," who targeted government organizations in Moldova and Tunisia. The exploit URLs in this case loaded malicious JavaScript on the target systems. On July 13, Zimbra published a securit...
Google: Hackers exploited Zimbra zero-day in attacks on govt orgs
BleepingComputer
·Bill Toulas
·Published Nov 17, 2023
·Updated
Affected Software
1 affected component
Zimbra Collaboration email server=8.8.15 Patch 41
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the exploitation of a zero-day vulnerability in the Zimbra Collaboration email server by hackers targeting government organizations.
2
What security implications are discussed?
The article highlights the serious risks posed by zero-day vulnerabilities, particularly their use in stealing sensitive data from government systems.
3
What products or software are affected?
The affected product is the Zimbra Collaboration email server, specifically version 8.8.15 Patch 41.
4
Who discovered the vulnerability being exploited?
The vulnerability was discovered by Google's Threat Analysis Group (TAG).
5
What types of organizations were targeted by the attacks?
The attacks primarily targeted government organizations across multiple countries.