National Cyber Warfare Foundation (NCWF)

Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files


0 user ratings
2025-10-06 07:04:02
milo
Blue Team (CND)
A now patched security vulnerability in Zimbra Collaboration was exploited as a zero-day earlier this year in cyber attacks targeting the Brazilian military.
Tracked as CVE-2025-27915 (CVSS score: 5.4), the vulnerability is a stored cross-site scripting (XSS) vulnerability in the Classic Web Client that arises as a result of insufficient sanitization of HTML content in ICS calendar files,



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/10/zimbra-zero-day-exploited-to-target.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.