View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Russian Hackers Exploit Zimbra Zero-Day in US and Ukraine Attacks

🚨 ACTIVE EXPLOITATION

  • Russian Hackers Exploit Zimbra Zero-Day in US and Ukraine Attacks — Dark Reading
    Russian state-sponsored hackers exploited a zero-day vulnerability in Zimbra Collaboration Suite targeting organizations in the US and Ukraine.
    • Targets include US and Ukraine organizations using Zimbra email servers
    • Vulnerability exploited is a zero-day in Zimbra Collaboration Suite
    • Attack delivered via 'half-click' phishing emails requiring only message preview or open
    • Threat actor identified as state-sponsored group 'Laundry Bear'

🕵️ RESEARCH & DEEP DIVES

  • New Dolphin X malware uses AI to rank and prioritize high-value victims — BleepingComputer
    Dolphin X malware employs AI to profile infected users and prioritize them for targeted credential theft and exploitation.
    • Targets infected users across more than 300 applications including browsers, crypto wallets, and password managers
    • Features an AI Profiler that analyzes app usage, risk scores, and installed software to assign risk ratings
    • AI-generated daily summaries help attackers prioritize high-value victims for credential theft and further exploitation
    • Credential-stealing capabilities include harvesting .env files, SSH keys, cloud tokens, and browser login data
    • Analysis based on operator panel and network traffic; live malware sample not executed or fully confirmed

🔓 CVEs & KEV

  • 20 CVEs reported, with the worst scoring 10.0 on CVSS.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check