Multiple cybersecurity agencies in Europe warned about a vulnerability affecting Zimbra’s email product that researchers have confirmed is being exploited to spread malware.
https://x.com/threatinsight/status/1841089939905134793
Researchers at email security company Proofpoint said they began to see exploitation of the bug, tracked as CVE-2024-45519, on September 28. Zimbra has released a patch
Other companies have published maps showing thousands of potentially vulnerable Zimbra instances across Europe.
netlas.io search
/nosanitize
https://app.netlas.io/responses/?q=certificate.issuer.common_name%3A"Vigor%20Router"&page=1&indices=
but several other experts said they are seeing mass targeting of the bug.
https://x.com/JusticeRage/status/1841017884245438555
National computer emergency response teams (CERTs) in Italy and Latvia have published warnings about the vulnerability while experts have released detailed proof of concept code
https://blog.projectdiscovery.io/zimbra-remote-code-execution/
Past vulnerabilities affecting Zimbra products were used to attack government agencies in Greece, Tunisia, Moldova, Vietnam and Pakistan.
https://therecord.media/hackers-target-govts-with-zimbra-zero