⤷ Title: Critical RCE Flaw Patched in Roundcube Webmail: Update Immediately!
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 03:06:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Deserialization #Email #firs0v #IMAP #patch #php #rce #Remote Code Execution #Roundcube #security #Vulnerability #webmail
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 03:06:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #Deserialization #Email #firs0v #IMAP #patch #php #rce #Remote Code Execution #Roundcube #security #Vulnerability #webmail
Daily CyberSecurity
Critical RCE Flaw Patched in Roundcube Webmail: Update Immediately!
Roundcube Webmail has patched a critical RCE vulnerability (CVE-2025-49113) allowing remote code execution post-authentication. Update to 1.6.2 or 1.5.10 immediately!
⤷ Title: CVE-2025-49113: Roundcube RCE Exploit Unveiled—The Swiss Army Knife of Webmail Just Got a Weaponized Blade
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 03:42:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49113 #PHP Object Injection #Remote Code Execution #Roundcube #Webmail Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 05 Jun 2025 03:42:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2025_49113 #PHP Object Injection #Remote Code Execution #Roundcube #Webmail Security
Daily CyberSecurity
CVE-2025-49113: Roundcube RCE Exploit Unveiled—The Swiss Army Knife of Webmail Just Got a Weaponized Blade
A critical RCE flaw (CVE-2025-49113) in Roundcube is under active exploitation with PoC sold on forums. Patch immediately to v1.5.10 or v1.6.11!
⤷ Title: UNC1151 Exploits Roundcube Flaw in Spear Phishing Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:35:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CERT Polska #Credential Theft #CVE_2024_42009 #cybersecurity #Roundcube #spear_phishing #UNC1151 #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 00:35:31 +0000
════════════════════════
⌗ Tags: #Cyber Security #Vulnerability Report #APT #CERT Polska #Credential Theft #CVE_2024_42009 #cybersecurity #Roundcube #spear_phishing #UNC1151 #webmail #XSS
Daily CyberSecurity
UNC1151 Exploits Roundcube Flaw in Spear Phishing Attack
CERT Polska warns of a critical Roundcube XSS flaw (CVE-2024-42009) exploited by UNC1151 in spear phishing, stealing credentials and compromising Polish organizations.
⤷ Title: CISA Flags Active Exploits in Erlang/OTP SSH and Roundcube Webmail: Critical RCE and XSS Flaws Under Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:01:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2024_42009 #CVE_2025_32433 #cybersecurity #Erlang/OTP #Exploit #KEV Catalog #rce #Roundcube #spear_phishing #Vulnerability #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:01:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2024_42009 #CVE_2025_32433 #cybersecurity #Erlang/OTP #Exploit #KEV Catalog #rce #Roundcube #spear_phishing #Vulnerability #XSS
Daily CyberSecurity
CISA Flags Active Exploits in Erlang/OTP SSH and Roundcube Webmail: Critical RCE and XSS Flaws Under Attack
CISA adds two critical vulnerabilities to KEV: Erlang/OTP (RCE) and Roundcube (XSS). Actively exploited, these flaws pose severe risks to systems and email accounts.
⤷ Title: TryHackMe | Roundcube: CVE-2025-49113 | WriteUp
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 17:06:34 GMT
════════════════════════
⌗ Tags: #roundcube #tryhackme_walkthrough #cve #tryhackme #tryhackme_writeup
════════════════════════
𐀪 Author: Axoloth
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 17:06:34 GMT
════════════════════════
⌗ Tags: #roundcube #tryhackme_walkthrough #cve #tryhackme #tryhackme_writeup
Medium
TryHackMe | Roundcube: CVE-2025-49113 | WriteUp
Exploit CVE-2025–49113 in a lab environment
⤷ Title: Outbound HackTheBox Walkthrough: Step-by-Step Exploitation & Privilege Escalation
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 17:49:27 GMT
════════════════════════
⌗ Tags: #cve_2025_49113 #hackthebox_writeup #cve_2025_27519 #roundcube_webmail #outbound_walkthrough
════════════════════════
𐀪 Author: Death Esther
════════════════════════
ⴵ Time: Fri, 15 Aug 2025 17:49:27 GMT
════════════════════════
⌗ Tags: #cve_2025_49113 #hackthebox_writeup #cve_2025_27519 #roundcube_webmail #outbound_walkthrough
Medium
Outbound HackTheBox Walkthrough — Hands-On Step-by-Step Guide
A complete guide to scanning, exploiting Roundcube Webmail, harvesting credentials, and gaining root access on Outbound HTB lab
⤷ Title: Outbound Writeup (HackTheBox Easy Machine)
════════════════════════
𐀪 Author: Ivan Daňo
════════════════════════
ⴵ Time: Sat, 15 Nov 2025 15:12:24 GMT
════════════════════════
⌗ Tags: #ctf #hackthebox_writeup #hacking #linux #roundcube
════════════════════════
𐀪 Author: Ivan Daňo
════════════════════════
ⴵ Time: Sat, 15 Nov 2025 15:12:24 GMT
════════════════════════
⌗ Tags: #ctf #hackthebox_writeup #hacking #linux #roundcube
Medium
Outbound Writeup (HackTheBox Easy Machine)
As is common in real life pentests, you will start the Outbound box with credentials for the following account tyler / LhKL1o9Nm3X2
⤷ Title: Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:38:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cross_Site Scripting #CSS Sanitizer #CVE_2025_68460 #CVE_2025_68461 #Email Security #Information Disclosure #Roundcube #SVG #webmail #XSS
Daily CyberSecurity
Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy
Roundcube patches two High-severity flaws: an SVG-based XSS and a CSS sanitizer bypass. Protect your inbox—update to v1.6.12 or v1.5.12 now.
⤷ Title: HTB: Outbound
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
════════════════════════
𐀪 Author: bluesnow
════════════════════════
ⴵ Time: Tue, 17 Feb 2026 07:42:30 GMT
════════════════════════
⌗ Tags: #roundcube #rce #below #insecure_deserialization #symlink_attack
Medium
HTB: Outbound
| Roundcube | PHP Deserialization | CVE-2025–49113 | 3DES Hash Decryption | Below | Symlink Attack |
⤷ Title: Inside the Arsenal: Exposed Server Reveals APT28’s ‘Roundish’ Toolkit and Advanced Cyber Espionage Tactics
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 04:56:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #CSS Side_Channel #cyber_espionage #cybersecurity #Fancy Bear #Hunt Intelligence #malware #Roundcube Vulnerability #Roundish Toolkit #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 16 Mar 2026 04:56:08 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT28 #CSS Side_Channel #cyber_espionage #cybersecurity #Fancy Bear #Hunt Intelligence #malware #Roundcube Vulnerability #Roundish Toolkit #threat intelligence
Daily CyberSecurity
Inside the Arsenal: Exposed Server Reveals APT28's 'Roundish' Toolkit and Advanced Cyber Espionage Tactics
Hunt Intelligence unmasks APT28's 'Roundish' toolkit from an exposed server, revealing advanced CSS side-channel attacks and stealthy Linux implants.
⤷ Title: Critical Roundcube Webmail Security Updates Fix Severe Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 02:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_48842 #Open Source Mail #Roundcube #security patch #sql injection #webmail #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 28 May 2026 02:00:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_48842 #Open Source Mail #Roundcube #security patch #sql injection #webmail #XSS
Daily CyberSecurity
Critical Roundcube Webmail Security Updates Fix Severe Flaws
Roundcube Webmail security updates address critical vulnerabilities, including pre-auth SQL injection and code evaluation flaws. Update your patch now.
⤷ Title: UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 11:54:48 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Canada #China #Cyber Attack #Cyber Crime #Cybersecurity #Privacy #Roundcube #security #University #UNK_MassTraction #USA #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 11:54:48 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Canada #China #Cyber Attack #Cyber Crime #Cybersecurity #Privacy #Roundcube #security #University #UNK_MassTraction #USA #Vulnerability
Hackread
UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities
China-linked UNK_MassTraction targets US and Canadian universities through Roundcube flaws, stealing sessions and opening access to research mail servers.
❤1
⤷ Title: Roundcube 1.7.2 Patches Zero-Click Stored XSS CVE-2026-54433
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 15:00:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_54432 #CVE_2026_54433 #Roundcube #Roundcube Webmail #ssrf #Stored XSS #Webmail Security #Zero_Click XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 15:00:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_54432 #CVE_2026_54433 #Roundcube #Roundcube Webmail #ssrf #Stored XSS #Webmail Security #Zero_Click XSS
Daily CyberSecurity
Roundcube 1.7.2 Patches Zero-Click Stored XSS CVE-2026-54433
TL;DR Roundcube shipped versions 1.7.2 and 1.6.17 to fix six security bugs. The headline flaw is a Roundcube zero-click XSS, tracked as CVE-2026-54433, in plain-text message rendering. The update …
⤷ Title: UNK_MassTraction Hits University Roundcube Servers
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 14:30:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China APT #CVE_2024_42009 #IceCube Malware #Proofpoint #Roundcube #University Cyberattack #UNK_MassTraction
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 14:30:03 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China APT #CVE_2024_42009 #IceCube Malware #Proofpoint #Roundcube #University Cyberattack #UNK_MassTraction
Information Security News
UNK_MassTraction Hits University Roundcube Servers
Sometimes a single opened email is all it takes to compromise a university network. Researchers at Proofpoint have uncovered a campaign they call UNK_MassTraction. A threat group believed to have …
⤷ Title: UNK_MassTraction Exploits Roundcube Webmail to Hit University Physics Departments
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 14:03:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_aligned #CVE_2024_42009 #CVE_2025_49113 #cyber_espionage #IceCube #Roundcube #UNK_MassTraction #VShell
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 13 Jul 2026 14:03:15 +0000
════════════════════════
⌗ Tags: #Cybercriminals #China_aligned #CVE_2024_42009 #CVE_2025_49113 #cyber_espionage #IceCube #Roundcube #UNK_MassTraction #VShell
Daily CyberSecurity
UNK_MassTraction Exploits Roundcube Webmail to Hit University Physics Departments
At a glance Actor UNK_MassTraction — suspected China-aligned espionage cluster Activity Roundcube exploitation for credential theft, webshells, and the VShell backdoor Targets Physics and engineer…
⤷ Title: Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 09:38:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Email Security #IMAP Command Injection #LDAP injection #Remote Code Execution #Roundcube #ssrf #Stored XSS #webmail
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 09:38:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Email Security #IMAP Command Injection #LDAP injection #Remote Code Execution #Roundcube #ssrf #Stored XSS #webmail
Daily CyberSecurity
Roundcube Patches RCE and SSRF Flaws in 1.6.18 and 1.7.3
Roundcube shipped two security updates this week. Also, versions 1.6.18 and 1.7.3 close eleven separate bugs. The worst Roundcube webmail RCE flaw sits in a spam-training plugin. Why It Matters We…