Russian hackers exploit Zimbra flaw to breach Ukrainian maritime agency

(Daryna Antoniuk – The Record) A Russian state-backed hacker group has targeted a Ukrainian government agency using a stealthy phishing campaign that exploits a vulnerability in widely used Zimbra webmail software, according to new research. The operation, attributed with medium confidence to APT28 — also known as Fancy Bear and believed to be linked to Russia’s military intelligence — targeted the State Hydrographic Service of Ukraine which plays a role in maritime navigation and other critical infrastructure services. Researchers at cybersecurity firm Seqrite said the attackers exploited a cross-site scripting flaw, tracked as CVE-2025-66376, allowing them to inject malicious code directly into an email viewed through Zimbra’s browser-based interface. – Russian hackers exploit Zimbra flaw to breach Ukrainian maritime agency | The Record from Recorded Future News

Latest articles

Related articles