Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    OpenAI co-founder Greg Brockman takes charge of product strategy

    May 17, 2026

    Marketing operating system Nectar Social raises $30M Series A led by Menlo

    May 17, 2026

    The haves and have nots of the AI gold rush

    May 17, 2026
    Facebook X (Twitter) Instagram
    Tech Pulse
    • OpenAI co-founder Greg Brockman takes charge of product strategy
    • Marketing operating system Nectar Social raises $30M Series A led by Menlo
    • The haves and have nots of the AI gold rush
    • Meridian Ventures launched $35M fund to back MBA-deferred founders
    • Lovable just backed a company that’s looking to bring vibe coding to hardware
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Techurz
    • Home
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    Techurz
    Home - Cyber Reality - Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files
    Cyber Reality

    Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files

    TechurzBy TechurzOctober 6, 2025Updated:May 10, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Zimbra Zero-Day
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 06, 2025Ravie LakshmananEmail Security / Zero-Day

    A now patched security vulnerability in Zimbra Collaboration was exploited as a zero-day earlier this year in cyber attacks targeting the Brazilian military.

    Tracked as CVE-2025-27915 (CVSS score: 5.4), the vulnerability is a stored cross-site scripting (XSS) vulnerability in the Classic Web Client that arises as a result of insufficient sanitization of HTML content in ICS calendar files, resulting in arbitrary code execution.

    “When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a tag,” according to a description of the flaw in the NIST National Vulnerability Database (NVD).

    “This allows an attacker to run arbitrary JavaScript within the victim’s session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim’s account, including e-mail redirection and data exfiltration.”

    The vulnerability was addressed by Zimbra as part of versions 9.0.0 Patch 44, 10.0.13, and 10.1.5 released on January 27, 2025. The advisory, however, makes no mention of it having been exploited in real-world attacks.

    However, according to a report published by StrikeReady Labs on September 30, 2025, the observed in-the-wild activity involved unknown threat actors spoofing the Libyan Navy’s Office of Protocol to target the Brazilian military using malicious ICS files that exploited the flaw.

    The ICS file contained a JavaScript code that’s designed to act as a comprehensive data stealer to siphon credentials, emails, contacts, and shared folders to an external server (“ffrk[.]net”). It also searches for emails in a specific folder, and adds malicious Zimbra email filter rules with the name “Correo” to forward the messages to spam_to_junk@proton.me.

    As a way to avoid detection, the script is fashioned such that it hides certain user interface elements and detonates only if more than three days have passed since the last time it was executed.

    It’s currently not clear who is behind the attack, but earlier this year, ESET revealed that the Russian threat actor known as APT28 had exploited XSS vulnerabilities in various webmail solutions from Roundcube, Horde, MDaemon, and Zimbra to obtain unauthorized access.

    A similar modus operandi has also been adopted by other hacking groups like Winter Vivern and UNC1151 (aka Ghostwriter) to facilitate credential theft.

    Brazilian exploited Files ICS Malicious Military target zeroday Zimbra
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCISOs rethink the security organization for the AI era
    Next Article Best Amazon Prime Day deals 2025: Our 85+ favorite sales this October
    Techurz
    • Website

    Related Posts

    Opinion

    Fintech startup Parker files for bankruptcy

    May 9, 2026
    Opinion

    AI chip startup Cerebras files for IPO

    April 18, 2026
    Opinion

    What the Epstein files reveal about EV startups and Silicon Valley

    February 15, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    • About Us
    • Contact Us
    • Editorial Policy
    • Our Authors / Editorial Team
    • Advertise
    • Write For Us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Sitemap

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.