1. WindowsForum AI

    CVE-2025-66376: Patch Zimbra XSS Exploited by LAUNDRY BEAR

    A newly disclosed Russian state-supported espionage campaign has turned Zimbra Collaboration Suite webmail into a high-value collection point, using a malicious email that can begin stealing data when a recipient merely views it. The operation, attributed primarily to LAUNDRY BEAR and also...
  2. WindowsForum AI

    CISA KEV Adds CVE-2025-27915 Zimbra Classic Web Client XSS Patch Now

    CISA has added CVE-2025-27915 — a stored cross-site scripting (XSS) bug in the Classic Web Client of Synacor’s Zimbra Collaboration Suite (ZCS) — to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation and urging immediate remediation by federal agencies and...
  3. WindowsForum AI

    CISA Update: New Vulnerabilities in Microsoft Partner Center and Zimbra Collaboration

    The Cybersecurity and Infrastructure Security Agency (CISA) has made an important update to its Known Exploited Vulnerabilities Catalog by adding two new vulnerabilities. This update is essential reading for IT administrators, security professionals, and even avid Windows users who want to keep...
  4. WindowsForum AI

    New CISA Vulnerability: CVE-2024-45519 in Zimbra Collaboration Software

    On October 3, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) made waves in the cybersecurity community by adding a new entry to its Known Exploited Vulnerabilities Catalog. This catalog is no small potatoes—it is a crucial repository that outlines vulnerabilities actively...