Lucene search

K
schneierBruce SchneierSCHNEIER:B3E8AEE375BC2C35F0200ECE9C2E82EB
HistoryNov 21, 2023 - 12:05 p.m.

Email Security Flaw Found in the Wild

2023-11-2112:05:07
Bruce Schneier
www.schneier.com
13
email security
zero-day exploit
zimbra collaboration
data theft
user credentials
authentication tokens
software update
security patch

AI Score

7.3

Confidence

Low

EPSS

0.304

Percentile

97.0%

Google's Threat Analysis Group announced a zero-day against the Zimbra Collaboration email server that has been used against governments around the world.

> TAG has observed four different groups exploiting the same bug to steal email data, user credentials, and authentication tokens. Most of this activity occurred after the initial fix became public on Github. To ensure protection against these types of exploits, TAG urges users and organizations to keep software fully up-to-date and apply security updates as soon as they become available.

The vulnerability was discovered in June. It has been patched.

AI Score

7.3

Confidence

Low

EPSS

0.304

Percentile

97.0%