Cybersecurity Alert: New Malware Attack Targets Zimbra and SharePoint Users
In a recent cybersecurity incident, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding vulnerabilities in the Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint. These flaws, actively exploited by attackers, pose a significant threat to government agencies and organizations using these platforms.
The vulnerabilities—CVE-2025-66376 and CVE-2026-20963—allow attackers to execute malicious code through email, potentially exposing sensitive information like passwords and session tokens. Victims of the ongoing campaign, dubbed Operation GhostMail, include users of Zimbra, particularly in Ukraine.
The impact of this attack is severe, with the potential for substantial data breaches. To protect against these threats, users are urged to apply patches for the identified vulnerabilities by their respective deadlines.
Risk Level: High. Cybersecurity measures should be prioritized to mitigate these risks effectively.
Source: View Original Report
