CyberSecurity News
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
AI summary
Threat actors are exploiting a patched vulnerability in Zimbra Collaboration Suite to deploy web shells and access mailbox data. The vulnerability, which has a CVSS score of 8.9, is an unauthenticated operating system command injection flaw that can lead to remote code execution. This flaw is being used to harvest authentication secrets. The Microsoft Security Research team has identified the exploitation of this vulnerability, which can be used when Simple Network Management Protocol is involved. The vulnerability has been assigned the identifier CVE-2022 is not mentioned but rather 2026-73570. Attackers are using this exploit to gain unauthorized access to mailbox data.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

