Find notable cyber news and cases, enriched with sources, timelines, and signals.

APT28 Operation GhostMail Zimbra phishing campaign targeting Ukrainian government entities

Campaign
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

APT28’s Operation GhostMail is actively targeting Ukrainian government entities through a phishing chain that exploits CVE-2025-66376 in Zimbra Collaboration Suite, creating immediate risk to email accounts and credentials. The message delivers an obfuscated JavaScript payload in the HTML body of a single email, avoiding attachments and macros. The payload can harvest session tokens, backup 2FA codes, browser-saved passwords, and mailbox content from the last 90 days. The activity matters because the vulnerability is already treated as exploited in the wild, and one named target is the Ukrainian State Hydrology Agency, a critical infrastructure entity.

Cases

Related Happenings

Zimbra Classic Web Client stored XSS cross-site scripting flaw

Vulnerability
H score26 First: 11.07.2026 09:45 Last: 11.07.2026 09:45 Sources 1

About this happening: Zimbra fixed a critical stored XSS flaw in the Classic Web Client that could let a specially crafted email run malicious code in a user's session. The weakness cou...

Zimbra Classic Web Client stored XSS security update

Security Patch Release
H score32 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: Zimbra released ZCS v10.1.19 to patch a stored XSS flaw in the Classic Web Client, narrowing exposure for users of that interface. The bug could be triggered through *...

Zimbra Classic Web Client stored XSS cross-site scripting flaw

Vulnerability
H score22 First: 10.07.2026 14:47 Last: 10.07.2026 14:47 Sources 1

About this happening: Zimbra's Classic Web Client stored cross-site scripting (XSS) flaw was patched in Zimbra 10.1.19, closing a path that could expose session data, account settings...

Synacor Zimbra CVE-2025-48700 security patch release

Security Patch Release
H score76 First: 24.04.2026 16:35 Last: 24.04.2026 16:35 Sources 1

About this happening: Synacor released security patches for CVE-2025-48700, fixing an XSS flaw in Zimbra Classic UI that could be triggered by a malicious email and expose sensiti...

Zimbra Collaboration Suite actively exploited XSS flaw (CVE-2025-48700)

Vulnerability
H score74 First: 24.04.2026 16:35 Last: 24.04.2026 16:35 Sources 1

About this happening: CVE-2025-48700 is an actively exploited XSS flaw in Zimbra Collaboration Suite (ZCS) that can let unauthenticated attackers run JavaScript inside a user's session and...

Timeline

  1. 19.03.2026 16:55 1 articles · 3mo ago

    CISA adds CVE-2025-66376 to exploited-in-the-wild catalog

    Legal Policy Action Update

    CISA added CVE-2025-66376, a stored XSS flaw in Zimbra Collaboration Suite (ZCS), to its catalog of vulnerabilities exploited in the wild and ordered Federal Civilian Executive Branch agencies to secure affected servers within two weeks under BOD 22-01.

    Show sources
  2. 19.03.2026 16:55 2 articles · 3mo ago

    APT28 Operation GhostMail targets Ukrainian government entities

    Initial Disclosure

    APT28, a Russia-linked GRU threat group, is exploiting CVE-2025-66376 in Zimbra Collaboration Suite (ZCS) against Ukrainian government entities through a phishing campaign called Operation GhostMail. The messages deliver an obfuscated JavaScript payload in the HTML body of a single email, and one named target is the Ukrainian State Hydrology Agency.

    Show sources