⤷ Title: Operation RoundPress: Sednit Weaponizes XSS to Breach Global Webmail Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:09:41 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #APT28 #CVE_2023_43770 #cyber_espionage #Cyberespionage #Fancy Bear #Operation RoundPress #russia #security #Sednit #SpyPress #Ukraine #webmail #webmail attacks #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 May 2025 00:09:41 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability #APT28 #CVE_2023_43770 #cyber_espionage #Cyberespionage #Fancy Bear #Operation RoundPress #russia #security #Sednit #SpyPress #Ukraine #webmail #webmail attacks #XSS
Daily CyberSecurity
Operation RoundPress: Sednit Weaponizes XSS to Breach Global Webmail Servers
Russia-linked APT28 (Sednit/Fancy Bear) targets vulnerable webmail with XSS in Operation RoundPress, stealing data from global entities.
⤷ Title: Critical RCE Flaw Patched in Roundcube Webmail: Update Immediately!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 03:06:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Deserialization #Email #firs0v #IMAP #patch #php #rce #Remote Code Execution #Roundcube #security #Vulnerability #webmail
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 03:06:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Deserialization #Email #firs0v #IMAP #patch #php #rce #Remote Code Execution #Roundcube #security #Vulnerability #webmail
Daily CyberSecurity
Critical RCE Flaw Patched in Roundcube Webmail: Update Immediately!
Roundcube Webmail has patched a critical RCE vulnerability (CVE-2025-49113) allowing remote code execution post-authentication. Update to 1.6.2 or 1.5.10 immediately!
⤷ Title: CVE-2025-49113: Roundcube RCE Exploit Unveiled—The Swiss Army Knife of Webmail Just Got a Weaponized Blade
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 03:42:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49113 #PHP Object Injection #Remote Code Execution #Roundcube #Webmail Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 03:42:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49113 #PHP Object Injection #Remote Code Execution #Roundcube #Webmail Security
Daily CyberSecurity
CVE-2025-49113: Roundcube RCE Exploit Unveiled—The Swiss Army Knife of Webmail Just Got a Weaponized Blade
A critical RCE flaw (CVE-2025-49113) in Roundcube is under active exploitation with PoC sold on forums. Patch immediately to v1.5.10 or v1.6.11!
⤷ Title: UNC1151 Exploits Roundcube Flaw in Spear Phishing Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:35:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CERT Polska #Credential Theft #CVE_2024_42009 #cybersecurity #Roundcube #spear_phishing #UNC1151 #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:35:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CERT Polska #Credential Theft #CVE_2024_42009 #cybersecurity #Roundcube #spear_phishing #UNC1151 #webmail #XSS
Daily CyberSecurity
UNC1151 Exploits Roundcube Flaw in Spear Phishing Attack
CERT Polska warns of a critical Roundcube XSS flaw (CVE-2024-42009) exploited by UNC1151 in spear phishing, stealing credentials and compromising Polish organizations.
⤷ Title: Zimbra XSS Zero-Day (CVE-2025-27915) Actively Exploited; CISA Adds to KEV Catalog
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 02:51:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Calendar Exploit #CISA KEV #CVE_2025_27915 #StrikeReady #Webmail Security #XSS #zero_day #Zimbra
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 02:51:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Calendar Exploit #CISA KEV #CVE_2025_27915 #StrikeReady #Webmail Security #XSS #zero_day #Zimbra
Daily CyberSecurity
Zimbra XSS Zero-Day (CVE-2025-27915) Actively Exploited; CISA Adds to KEV Catalog
CISA added the Zimbra XSS zero-day (CVE-2025-27915) to its KEV Catalog due to active exploitation since January. Attackers use malicious .ICS files to steal mail data.
⤷ Title: Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
Daily CyberSecurity
Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
Roundcube patches two High-severity flaws: an SVG-based XSS and a CSS sanitizer bypass. Protect your inbox—update to v1.6.12 or v1.5.12 now.
⤷ Title: Critical Roundcube Webmail Security Updates Fix Severe Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 02:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_48842 #Open Source Mail #Roundcube #security patch #sql injection #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 02:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_48842 #Open Source Mail #Roundcube #security patch #sql injection #webmail #XSS
Daily CyberSecurity
Critical Roundcube Webmail Security Updates Fix Severe Flaws
Roundcube Webmail security updates address critical vulnerabilities, including pre-auth SQL injection and code evaluation flaws. Update your patch now.
⤷ Title: Roundcube 1.7.2 Patches Zero-Click Stored XSS CVE-2026-54433
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 15:00:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_54432 #CVE_2026_54433 #Roundcube #Roundcube Webmail #ssrf #Stored XSS #Webmail Security #Zero_Click XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 15:00:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_54432 #CVE_2026_54433 #Roundcube #Roundcube Webmail #ssrf #Stored XSS #Webmail Security #Zero_Click XSS
Daily CyberSecurity
Roundcube 1.7.2 Patches Zero-Click Stored XSS CVE-2026-54433
TL;DR Roundcube shipped versions 1.7.2 and 1.6.17 to fix six security bugs. The headline flaw is a Roundcube zero-click XSS, tracked as CVE-2026-54433, in plain-text message rendering. The update …
⤷ Title: TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 14:44:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #half_click exploits #Proofpoint #SpyPress #TA458 #TA488 #webmail zero_days #Zimbra #ZimReaper
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 14:44:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #half_click exploits #Proofpoint #SpyPress #TA458 #TA488 #webmail zero_days #Zimbra #ZimReaper
Daily CyberSecurity
TA488 and TA458 Steal Government Email Using Half-Click Webmail Exploits
At a Glance Actor or group TA488 (Void Blizzard, Laundry Bear) and TA458 (Operation RoundPress), both Russia-aligned Activity type Espionage via cross-site scripting flaws in webmail; credential a…
⤷ Title: Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 09:38:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Email Security #IMAP Command Injection #LDAP injection #Remote Code Execution #Roundcube #ssrf #Stored XSS #webmail
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 09:38:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Email Security #IMAP Command Injection #LDAP injection #Remote Code Execution #Roundcube #ssrf #Stored XSS #webmail
Daily CyberSecurity
Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3
Roundcube shipped two security updates this week. Also, versions 1.6.18 and 1.7.3 close eleven separate bugs. The worst Roundcube webmail RCE flaw sits in a spam-training plugin. Why It Matters We…