ESPN Deportes¿Puede ser sancionado Cristiano según el reglamento?RTP DesportoEm ambiente conturbado. Portugal defronta Dinamarca após saída de Cristiano RonaldoESPNWhy Darnell Washington has become the Steelers' X factorThe Jerusalem PostIDF: 170 Hamas, PIJ terrorists killed in Gaza were misrepresented as 'innocent journalists'ColliderThe Fate of 'Reacher's First Spin-Off Has Officially Been DecidedThe Hollywood Reporter‘Reacher’ Spinoff ‘Neagley’ Renewed for Season 2 at Prime VideoDeadline‘Reacher’ Spinoff ‘Neagley’ Renewed For Season 2 At Amazon7sur7Les États-Unis durcissent à nouveau leur régime de sanctions contre l’IranSRF NewsKrieg in der Ukraine – Russische Drohnen treffen Schule und Südbrücke in KiewBBC NewsMan City not 'above the rules', says No 10 after backlash to Burnham remarksPremium TimesUnsettled by students’ poor performance, Akwa Ibom disputes report published by PREMIUM TIMESMintTaylor Swift’s former Beverly Hills home, where she wrote ‘1989’, is up for sale at nearly $8 million: See what’s inside
The Daily Newsstand · Free, Always
Thursday, October 1, 2026

Microsoft catches hackers exploiting Zimbra bug before disclosure

Translate

Attackers were probing the mail server flaw weeks before it had a CVE to its name

Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems.

Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers.

No stolen password or unfortunate employee clicking a dodgy link is required. An attacker can send a specially crafted email to a vulnerable internet-facing server and potentially run commands, though Redmond notes the flaw affects only servers running Zimbra's optional SNMP monitoring package with notifications enabled.

REG AD

Zimbra fixed the flaw in version 10.1.20 on July 20, but CVE-2026-73570 wasn't publicly disclosed until August 13. Between July 28 and August 7, Redmond spotted two different scanning tools probing the same part of Zimbra later used in attacks.

REG AD

At first, the activity appears to have focused on finding vulnerable servers and testing the flaw. The attackers used a collection of common network utilities to make vulnerable systems call back to infrastructure they controlled, confirming they could execute commands.

Once they found servers that played ball, things got messier. Microsoft's investigation found attackers deploying web shells and reverse shells, escalating their privileges, installing tools for persistent remote access, and running malicious code directly in memory.

Some even tidied up after themselves. Microsoft said attackers temporarily changed permissions on public directories to plant web shells, then restored the original settings afterward in an apparent attempt to make their meddling harder to spot.

The intruders also explored the wider Zimbra environments they landed in, identifying other mail servers and looking for trusted connections they could use to move between them. In some cases, existing SSH relationships between Zimbra systems gave them a route to neighboring servers.

On at least one compromised machine, attackers turned their initial foothold into root access. They then set things up to keep running commands with the highest privileges without needing a password.

Mailboxes were, unsurprisingly, also on the shopping list. Microsoft said attackers hunted for Zimbra credentials and authentication secrets that could potentially be used to access user accounts. One malicious tool it uncovered was built specifically to extract service account credentials and pull mailbox information from Zimbra's databases.

In another incident, attackers bundled recent mailbox backups into an archive and tried to ship the haul to Azure Blob Storage using Microsoft's own AzCopy utility. Microsoft said it couldn't confirm from the evidence available whether the transfer actually succeeded.

The company saw affected organizations across multiple regions and industries, with the attacks ranging from automated exploitation to more deliberate hands-on-keyboard activity. It hasn't attributed the activity to a particular crew.

REG AD

Admins running versions earlier than Zimbra 10.1.20 should update to 10.1.20 or later, while those unable to patch can reduce their exposure by removing the optional SNMP package or disabling SNMP notifications.

Attackers, meanwhile, appear to have gotten there early, with Microsoft spotting probes for the flaw more than two weeks before it was publicly disclosed. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.