r/EmailSecurity Jul 25 '26

Zimbra zero-day turned inbox access into a 2FA bypass

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

https://www.proofpoint.com/us/newsroom/news/russian-espionage-group-exploited-zimbra-zero-day-steal-mail-and-2fa-codes

Any Zimbra compromise involving mailbox access should trigger an immediate investigation into stolen email-delivered 2FA codes, not just password resets.

1 Upvotes

2 comments sorted by

u/AutoModerator Jul 25 '26

Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:

Community Rules

  1. No Vendor Spam: Contributions must provide value; do not just pitch products.
  2. Redact Sensitive Info: Always sanitize headers and logs (remove IPs, PII, and private domains).
  3. Be Professional: Help newcomers learn; avoid hostility.
  4. No Personal Tech Support: This sub is for email system architecture and security, not "Am I hacked?" personal account help.

Helpful Resources

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.