⤷ Title: Critical RCE Flaw Patched in Roundcube Webmail: Update Immediately!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 03:06:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Deserialization #Email #firs0v #IMAP #patch #php #rce #Remote Code Execution #Roundcube #security #Vulnerability #webmail
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 03:06:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Deserialization #Email #firs0v #IMAP #patch #php #rce #Remote Code Execution #Roundcube #security #Vulnerability #webmail
Daily CyberSecurity
Critical RCE Flaw Patched in Roundcube Webmail: Update Immediately!
Roundcube Webmail has patched a critical RCE vulnerability (CVE-2025-49113) allowing remote code execution post-authentication. Update to 1.6.2 or 1.5.10 immediately!
⤷ Title: CVE-2025-49113: Roundcube RCE Exploit Unveiled—The Swiss Army Knife of Webmail Just Got a Weaponized Blade
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 03:42:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49113 #PHP Object Injection #Remote Code Execution #Roundcube #Webmail Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 03:42:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49113 #PHP Object Injection #Remote Code Execution #Roundcube #Webmail Security
Daily CyberSecurity
CVE-2025-49113: Roundcube RCE Exploit Unveiled—The Swiss Army Knife of Webmail Just Got a Weaponized Blade
A critical RCE flaw (CVE-2025-49113) in Roundcube is under active exploitation with PoC sold on forums. Patch immediately to v1.5.10 or v1.6.11!
⤷ Title: UNC1151 Exploits Roundcube Flaw in Spear Phishing Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:35:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CERT Polska #Credential Theft #CVE_2024_42009 #cybersecurity #Roundcube #spear_phishing #UNC1151 #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:35:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CERT Polska #Credential Theft #CVE_2024_42009 #cybersecurity #Roundcube #spear_phishing #UNC1151 #webmail #XSS
Daily CyberSecurity
UNC1151 Exploits Roundcube Flaw in Spear Phishing Attack
CERT Polska warns of a critical Roundcube XSS flaw (CVE-2024-42009) exploited by UNC1151 in spear phishing, stealing credentials and compromising Polish organizations.
⤷ Title: CISA Flags Active Exploits in Erlang/OTP SSH and Roundcube Webmail: Critical RCE and XSS Flaws Under Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:01:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2024_42009 #CVE_2025_32433 #cybersecurity #Erlang/OTP #Exploit #KEV Catalog #rce #Roundcube #spear_phishing #Vulnerability #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:01:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2024_42009 #CVE_2025_32433 #cybersecurity #Erlang/OTP #Exploit #KEV Catalog #rce #Roundcube #spear_phishing #Vulnerability #XSS
Daily CyberSecurity
CISA Flags Active Exploits in Erlang/OTP SSH and Roundcube Webmail: Critical RCE and XSS Flaws Under Attack
CISA adds two critical vulnerabilities to KEV: Erlang/OTP (RCE) and Roundcube (XSS). Actively exploited, these flaws pose severe risks to systems and email accounts.
⤷ Title: TryHackMe | Roundcube: CVE-2025-49113 | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 17:06:34 GMT
════════════════════════
⌗ Tags: #roundcube #tryhackme_walkthrough #cve #tryhackme #tryhackme_writeup
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 17:06:34 GMT
════════════════════════
⌗ Tags: #roundcube #tryhackme_walkthrough #cve #tryhackme #tryhackme_writeup
Medium
TryHackMe | Roundcube: CVE-2025-49113 | WriteUp
Exploit CVE-2025–49113 in a lab environment
⤷ Title: Outbound HackTheBox Walkthrough: Step-by-Step Exploitation & Privilege Escalation
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 17:49:27 GMT
════════════════════════
⌗ Tags: #cve_2025_49113 #hackthebox_writeup #cve_2025_27519 #roundcube_webmail #outbound_walkthrough
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 17:49:27 GMT
════════════════════════
⌗ Tags: #cve_2025_49113 #hackthebox_writeup #cve_2025_27519 #roundcube_webmail #outbound_walkthrough
Medium
Outbound HackTheBox Walkthrough — Hands-On Step-by-Step Guide
A complete guide to scanning, exploiting Roundcube Webmail, harvesting credentials, and gaining root access on Outbound HTB lab
⤷ Title: Outbound Writeup (HackTheBox Easy Machine)
════════════════════════
𐀪 Author: Ivan Daňo
════════════════════════
ⴵ Time: Sat, 15 Nov 2025 15:12:24 GMT
════════════════════════
⌗ Tags: #ctf #hackthebox_writeup #hacking #linux #roundcube
════════════════════════
𐀪 Author: Ivan Daňo
════════════════════════
ⴵ Time: Sat, 15 Nov 2025 15:12:24 GMT
════════════════════════
⌗ Tags: #ctf #hackthebox_writeup #hacking #linux #roundcube
Medium
Outbound Writeup (HackTheBox Easy Machine)
As is common in real life pentests, you will start the Outbound box with credentials for the following account tyler / LhKL1o9Nm3X2
⤷ Title: Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
Daily CyberSecurity
Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
Roundcube patches two High-severity flaws: an SVG-based XSS and a CSS sanitizer bypass. Protect your inbox—update to v1.6.12 or v1.5.12 now.
⤷ Title: HTB: Outbound
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
Medium
HTB: Outbound
| Roundcube | PHP Deserialization | CVE-2025–49113 | 3DES Hash Decryption | Below | Symlink Attack |
⤷ Title: Inside the Arsenal: Exposed Server Reveals APT28’s ‘Roundish’ Toolkit and Advanced Cyber Espionage Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 04:56:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #CSS Side_Channel #cyber_espionage #cybersecurity #Fancy Bear #Hunt Intelligence #malware #Roundcube Vulnerability #Roundish Toolkit #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 04:56:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #CSS Side_Channel #cyber_espionage #cybersecurity #Fancy Bear #Hunt Intelligence #malware #Roundcube Vulnerability #Roundish Toolkit #threat intelligence
Daily CyberSecurity
Inside the Arsenal: Exposed Server Reveals APT28's 'Roundish' Toolkit and Advanced Cyber Espionage Tactics
Hunt Intelligence unmasks APT28's 'Roundish' toolkit from an exposed server, revealing advanced CSS side-channel attacks and stealthy Linux implants.
⤷ Title: Critical Roundcube Webmail Security Updates Fix Severe Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 02:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_48842 #Open Source Mail #Roundcube #security patch #sql injection #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 02:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_48842 #Open Source Mail #Roundcube #security patch #sql injection #webmail #XSS
Daily CyberSecurity
Critical Roundcube Webmail Security Updates Fix Severe Flaws
Roundcube Webmail security updates address critical vulnerabilities, including pre-auth SQL injection and code evaluation flaws. Update your patch now.
⤷ Title: UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 11:54:48 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Canada #China #Cyber Attack #Cyber Crime #Cybersecurity #Privacy #Roundcube #security #University #UNK_MassTraction #USA #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 11:54:48 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Canada #China #Cyber Attack #Cyber Crime #Cybersecurity #Privacy #Roundcube #security #University #UNK_MassTraction #USA #Vulnerability
Hackread
UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities
China-linked UNK_MassTraction targets US and Canadian universities through Roundcube flaws, stealing sessions and opening access to research mail servers.
❤1
⤷ Title: Roundcube 1.7.2 Patches Zero-Click Stored XSS CVE-2026-54433
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 15:00:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_54432 #CVE_2026_54433 #Roundcube #Roundcube Webmail #ssrf #Stored XSS #Webmail Security #Zero_Click XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 15:00:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_54432 #CVE_2026_54433 #Roundcube #Roundcube Webmail #ssrf #Stored XSS #Webmail Security #Zero_Click XSS
Daily CyberSecurity
Roundcube 1.7.2 Patches Zero-Click Stored XSS CVE-2026-54433
TL;DR Roundcube shipped versions 1.7.2 and 1.6.17 to fix six security bugs. The headline flaw is a Roundcube zero-click XSS, tracked as CVE-2026-54433, in plain-text message rendering. The update …
⤷ Title: UNK_MassTraction Hits University Roundcube Servers
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 14:30:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China APT #CVE_2024_42009 #IceCube Malware #Proofpoint #Roundcube #University Cyberattack #UNK_MassTraction
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 14:30:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China APT #CVE_2024_42009 #IceCube Malware #Proofpoint #Roundcube #University Cyberattack #UNK_MassTraction
Information Security News
UNK_MassTraction Hits University Roundcube Servers
Sometimes a single opened email is all it takes to compromise a university network. Researchers at Proofpoint have uncovered a campaign they call UNK_MassTraction. A threat group believed to have …
⤷ Title: UNK_MassTraction Exploits Roundcube Webmail to Hit University Physics Departments
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 14:03:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_aligned #CVE_2024_42009 #CVE_2025_49113 #cyber_espionage #IceCube #Roundcube #UNK_MassTraction #VShell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 14:03:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_aligned #CVE_2024_42009 #CVE_2025_49113 #cyber_espionage #IceCube #Roundcube #UNK_MassTraction #VShell
Daily CyberSecurity
UNK_MassTraction Exploits Roundcube Webmail to Hit University Physics Departments
At a glance Actor UNK_MassTraction — suspected China-aligned espionage cluster Activity Roundcube exploitation for credential theft, webshells, and the VShell backdoor Targets Physics and engineer…