CISA Alerts: Zimbra & SharePoint Flaws Exploited in Ransomware

Date:

Cybersecurity Alert: New Malware Attack Targets Zimbra and SharePoint Users

In a recent cybersecurity incident, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding vulnerabilities in the Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint. These flaws, actively exploited by attackers, pose a significant threat to government agencies and organizations using these platforms.

The vulnerabilities—CVE-2025-66376 and CVE-2026-20963—allow attackers to execute malicious code through email, potentially exposing sensitive information like passwords and session tokens. Victims of the ongoing campaign, dubbed Operation GhostMail, include users of Zimbra, particularly in Ukraine.

The impact of this attack is severe, with the potential for substantial data breaches. To protect against these threats, users are urged to apply patches for the identified vulnerabilities by their respective deadlines.

Risk Level: High. Cybersecurity measures should be prioritized to mitigate these risks effectively.

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...