HackerFeeds

CyberSecurity News

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

The Hacker News
· July 23, 2026

AI summary

A Russian state-supported espionage group exploited a previously unknown vulnerability in Zimbra's webmail client to access Western mailboxes for months. The group's payload targeted the last 90 days of email, the entire email directory, saved browser passwords, and two-factor recovery codes. Simply opening a malicious message was sufficient to trigger the payload. The NSA, CISA, and other partner agencies have published information about the incident. The vulnerability allowed the group to steal sensitive information, including emails and authentication codes. The attack highlights the group's ability to exploit unknown flaws to gain unauthorized access to sensitive data.

Read the full article at The Hacker Newsthehackernews.com/2026/07/russian-espionage-group-exploited.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.