Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    City Detect, which uses AI to help cities stay safe and clean, raises $13M Series A

    March 6, 2026

    Cluely CEO Roy Lee admits to publicly lying about revenue numbers last year

    March 6, 2026

    DiligenceSquared uses AI, voice agents to make M&A research affordable

    March 5, 2026
    Facebook X (Twitter) Instagram
    Trending
    • City Detect, which uses AI to help cities stay safe and clean, raises $13M Series A
    • Cluely CEO Roy Lee admits to publicly lying about revenue numbers last year
    • DiligenceSquared uses AI, voice agents to make M&A research affordable
    • Science Corp. raises $230M as it races to bring its brain implant to market
    • Hardware testing startup Nominal hits $1B valuation, raises $155M in 10 months
    • EXCLUSIVE: Luma launches creative AI agents powered by its new ‘Unified Intelligence’ models
    • Zeno raises $25M to speed up production of its battery-swap motorbikes
    • How 1,000+ customer calls shaped a breakout enterprise AI startup
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Alternatives to Microsoft Outlook webmail come under attack in Europe
    Security

    Alternatives to Microsoft Outlook webmail come under attack in Europe

    TechurzBy TechurzMay 15, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Tech Spotlight   >   Cloud [CW]   >   Conceptual image of cloud-based email deployment.
    Share
    Facebook Twitter LinkedIn Pinterest Email


    “Over the past two years, webmail servers such as Roundcube and Zimbra have been a major target for several espionage groups such as Sednit, GreenCube, and Winter Vivern,” said ESET’s Faou. “Because many organizations don’t keep their webmail servers up to date, and because the vulnerabilities can be triggered remotely by sending an email message, it is very convenient for attackers to target such servers for email theft.”

    The most important thing for CISOs is to keep the webmail applications up to date, he said. “While we do mention in our research the use of zero-day vulnerabilities, in most of the incidents we analyzed, only known vulnerabilities, which had been patched for months, were used. Another hardening avenue, but probably too extreme for most organizations, is to forbid HTML content in emails, and just display raw text. However, this would prevent the use some functionalities such as text formatting (bold, italic, etc.) or the inclusion of hyperlinks.”

    Webmail can be described as a website that displays untrusted HTML content in a browser, he said. While most webmail systems sanitize the content to remove harmful HTML elements, which could execute JavaScript code, ESET’s research shows that the sanitizers are not without flaws and that attackers are able to bypass them. As a result, he said, by sending a specially crafted email, attackers are able to execute arbitrary JavaScript code in the context of their target’s browser. While this doesn’t lead to the compromise of the computer, he pointed out, executing JavaScript code in the context of the browser enables to steal information from the mailbox, for example, emails or the list of contacts.

    Alternatives Attack Europe Microsoft Outlook webmail
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe Huawei Watch 5 looks so good, I almost don’t care that it struggles to run any third-party apps
    Next Article The Download: Montana’s experimental treatments, and Google DeepMind’s new AI agent
    Techurz
    • Website

    Related Posts

    Opinion

    Tiger Global and Microsoft to fully exit Walmart-backed PhonePe via its IPO

    January 22, 2026
    Opinion

    Tiger Global, Microsoft to fully exit Walmart-backed PhonePe via its IPO

    January 22, 2026
    Security

    AI is becoming introspective – and that ‘should be monitored carefully,’ warns Anthropic

    November 3, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,286 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,286 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Our Picks

    City Detect, which uses AI to help cities stay safe and clean, raises $13M Series A

    March 6, 2026

    Cluely CEO Roy Lee admits to publicly lying about revenue numbers last year

    March 6, 2026

    DiligenceSquared uses AI, voice agents to make M&A research affordable

    March 5, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.