Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Spies hack high-value mail servers using an exploit from yesteryear
    • Today’s NYT Mini Crossword Answers for May 15
    • Co-op says shelves to be more fully stocked this weekend
    • Which One Suits You Best?
    • Police tech can sidestep facial recognition bans now
    • How one manufacturer turned uncertainty into a 16-month ROI
    • Tirzepatide outperforms semaglutide in weight loss clinical trial
    • “Be.EV is going places” – British EV charging network signs €23 million deal to install charging bays across the UK
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Thursday, May 15
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Spies hack high-value mail servers using an exploit from yesteryear
    News

    Spies hack high-value mail servers using an exploit from yesteryear

    Editor Times FeaturedBy Editor Times FeaturedMay 15, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    Menace actors, seemingly supported by the Russian authorities, hacked a number of high-value mail servers world wide by exploiting XSS vulnerabilities, a category of bug that was among the many mostly exploited in a long time previous.

    XSS is brief for cross-site scripting. Vulnerabilities end result from programming errors present in webserver software program that, when exploited, enable attackers to execute malicious code within the browsers of individuals visiting an affected web site. XSS first acquired consideration in 2005, with the creation of the Samy Worm, which knocked MySpace out of fee when it added a couple of million MySpace mates to a person named Samy. XSS exploits abounded for the subsequent decade and have progressively fizzled extra just lately, though this class of assaults continues now.

    Simply add JavaScript

    On Thursday, safety agency ESET reported that Sednit, a Kremlin-backed hacking group additionally tracked as APT28, Fancy Bear, Forest Blizzard, and Sofacy—gained entry to high-value e mail accounts by exploiting XSS vulnerabilities in mail server software program from 4 totally different makers. These packages are: Roundcube, MDaemon, Horde, and Zimbra.

    The hacks most just lately focused mail servers utilized by protection contractors in Bulgaria and Romania, a few of that are producing Soviet-era weapons to be used in Ukraine because it fends off an invasion from Russia. Governmental organizations in these international locations had been additionally focused. Different targets have included governments in Africa, the European Union, and South America.

    RoundPress, as ESET has named the operation, delivered XSS exploits via spearphishing emails. Hidden inside a few of the HTML within the emails was an XSS exploit. In 2023, ESET noticed Sednit exploiting CVE-2020-43770, a vulnerability that has since been patched in Roundcube. A 12 months later, ESET watched Sednit exploit totally different XSS vulnerabilities in Horde, MDaemon, and Zimbra. One of many now-patched vulnerabilities, from MDaemon, was a zero-day on the time Sednit exploited it.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    New Lego-building AI creates models that actually stand up in real life

    May 12, 2025

    Fidji Simo joins OpenAI as new CEO of Applications

    May 8, 2025

    Microsoft’s new “passwordless by default” is great but comes at a cost

    May 5, 2025

    Time saved by AI offset by new work created, study suggests

    May 2, 2025

    iOS and Android juice jacking defenses have been trivial to bypass for years

    April 28, 2025

    New Android spyware is targeting Russian military personnel on the front lines

    April 25, 2025
    Leave A Reply Cancel Reply

    Editors Picks

    Spies hack high-value mail servers using an exploit from yesteryear

    May 15, 2025

    Today’s NYT Mini Crossword Answers for May 15

    May 15, 2025

    Co-op says shelves to be more fully stocked this weekend

    May 14, 2025

    Which One Suits You Best?

    May 14, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Widely used DNA sequencer still doesn’t enforce Secure Boot

    January 31, 2025

    BBC complains to Apple over misleading shooting headline

    December 15, 2024

    This Startup Wants YouTube Creators to Get Paid for AI Training Data

    October 1, 2024
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.