Critical Zimbra RCE vulnerability under mass exploitation (CVE-2024-45519)

Attackers are actively exploiting CVE-2024-45519, a critical Zimbra vulnerability that allows them to execute arbitrary commands on vulnerable installations. Proofpoint’s threat researchers say that the attacks started on September 28 – sev… Continue reading Critical Zimbra RCE vulnerability under mass exploitation (CVE-2024-45519)

Critical XSS vulnerability in Zimbra exploited in the wild (CVE-2023-34192)

A critical cross site scripting (XSS) vulnerability (CVE-2023-34192) in popular open source email collaboration suite Zimbra is being exploited by attackers. About the vulnerability (CVE-2023-34192) CVE-2023-34192 could allow a remote authenticated thr… Continue reading Critical XSS vulnerability in Zimbra exploited in the wild (CVE-2023-34192)

Unpatched Zimbra RCE bug exploited by attackers (CVE-2022-41352)

A still unpatched vulnerability (CVE-2022-41352) in Zimbra Collaboration is being exploited by attackers to achieve remote code execution on vulnerable servers. About the vulnerability Zimbra Collaboration (formerly Zimbra Collaboration Suite) is cloud… Continue reading Unpatched Zimbra RCE bug exploited by attackers (CVE-2022-41352)

Synacor Zimbra Cloud: Supporting multiple collaboration tools from an email-centric workspace

Synacor unveiled its flagship Zimbra Cloud collaboration suite for small and medium businesses and prosumers, via Zimbra Gold Partner XMission. Zimbra Cloud is based on the popular Zimbra platform, trusted by thousands of businesses and used by tens of… Continue reading Synacor Zimbra Cloud: Supporting multiple collaboration tools from an email-centric workspace

More compromised windstream email sending malspam with Orion keylogger

Following on from Last Friday, it is looking like Windstream, Zimbra & Synacor still have a problem with accounts being compromised and mass malspam being sent.  Generally speaking the majority of ISPs are pretty good with blocking outgoing spam &#… Continue reading More compromised windstream email sending malspam with Orion keylogger