Product
Zimbra
- First Reported
- Oct 1, 2025
- Latest Reported
- Mar 11, 2026
Reported Context (2)
- two years, APT28 has systematically targeted webmail platforms, including Roundcube, Horde, MDaemon, and Zimbra, through XSS vulnerabilities to steal credentials, emails, and contacts from government and defense Hunt.io Links Roundcube Exploitation Toolkit Targeting Ukraine to APT28
- Phishing Infrastructure at Scale: Over 50+ malicious domains uncovered across Netlify, pages.dev, workers.dev, and b4a.run, hosting fake Outlook/Zimbra portals and credential harvesting pages. Hunt.io Details SideWinder Phishing and Malware Campaign Targeting South Asia
Malware (5)
People (3)
Threat Actors (4)
MITRE ATT&CK (20)
Vendors (6)
Products (12)
Tools (8)
Industries (8)
Countries (11)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.