Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’

A Russian state-linked threat actor has launched a targeted cyberattack against a Ukrainian government agency, exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite to steal credentials and sensitive email data. Dubbed “Operation GhostMail,” the campaign stands out for its complete absence of traditional attack indicators — no malicious file attachments, no suspicious links, […]

The post Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’ appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: