⤷ Title: Zimbra Zero-Day (CVE-2025-27915) Actively Exploited to Steal Credentials via Malicious Calendar Invites
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:46:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Theft #CVE_2025_27915 #Cyber Espionage #ICS File #StrikeReady #XSS #zero_day #Zimbra
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 03:46:58 +0000
════════════════════════
⌗ Tags: #Vulnerability #Credential Theft #CVE_2025_27915 #Cyber Espionage #ICS File #StrikeReady #XSS #zero_day #Zimbra
Penetration Testing Tools
Zimbra Zero-Day (CVE-2025-27915) Actively Exploited to Steal Credentials via Malicious Calendar Invites
A ZCS zero-day (CVE-2025-27915, CVSS 7.8) was actively exploited since Jan. 2025. Attackers used malicious calendar .ICS files to inject XSS and steal Zimbra webmail credentials.
⤷ Title: Zimbra XSS Zero-Day (CVE-2025-27915) Actively Exploited; CISA Adds to KEV Catalog
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 02:51:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Calendar Exploit #CISA KEV #CVE_2025_27915 #StrikeReady #Webmail Security #XSS #zero_day #Zimbra
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Oct 2025 02:51:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Calendar Exploit #CISA KEV #CVE_2025_27915 #StrikeReady #Webmail Security #XSS #zero_day #Zimbra
Daily CyberSecurity
Zimbra XSS Zero-Day (CVE-2025-27915) Actively Exploited; CISA Adds to KEV Catalog
CISA added the Zimbra XSS zero-day (CVE-2025-27915) to its KEV Catalog due to active exploitation since January. Attackers use malicious .ICS files to steal mail data.
⤷ Title: Blurred Deception: Russian APT Targets Transnistria and NATO with High-Pressure Phishing Lures
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:37:04 +0000
════════════════════════
⌗ Tags: #Cyber Security #Credential Harvesting #CSS Blur #HTML Malware #NATO #phishing #Russian APT #social engineering #StrikeReady Labs #Transnistria
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 00:37:04 +0000
════════════════════════
⌗ Tags: #Cyber Security #Credential Harvesting #CSS Blur #HTML Malware #NATO #phishing #Russian APT #social engineering #StrikeReady Labs #Transnistria
Daily CyberSecurity
Blurred Deception: Russian APT Targets Transnistria and NATO with High-Pressure Phishing Lures
A Russian APT is targeting Transnistria and NATO entities using blurred HTML attachments to harvest credentials. The 2025 campaign mimics official presidential decrees.