EmailDiscussions.com  

Go Back   EmailDiscussions.com > Discussions about Email Services > Email Comments, Questions and Miscellaneous
Register FAQ Members List Calendar Today's Posts
Stay in touch wirelessly

Email Comments, Questions and Miscellaneous Share your opinion of the email service you're using. Post general email questions and discussions that don't fit elsewhere.

Reply
 
Thread Tools
Old 26 Oct 2023, 01:50 AM   #1
malcontent
Essential Contributor
 
Join Date: Oct 2008
Posts: 275
European govt email servers hacked using Roundcube zero-day

Quote:
The Winter Vivern Russian hacking group has been exploiting a Roundcube Webmail zero-day in attacks targeting European government entities and think tanks since at least October 11.

The Roundcube development team released security updates fixing the Stored Cross-Site Scripting (XSS) vulnerability (CVE-2023-5631) reported by ESET researchers on October 16.

These security patches were pushed five days after the Slovak cybersecurity company detected Russian threat actors using the zero-day in real-world attacks.

European govt email servers hacked using Roundcube zero-day
malcontent is offline   Reply With Quote

Old 28 Oct 2023, 07:55 AM   #2
jarland
Essential Contributor
 
Join Date: Apr 2014
Posts: 399

Representative of:
MXRoute.com
See I have a big problem with the way bleepingcomputer phrased this article. Their language leaves no room for interpretation: "email servers hacked." It means there was an intrusion into their servers.

But that's not what XSS does. Besides, an XSS vulnerability in Roundcube is about as common as lunch. The moment I saw that there was a CVE my first thought was "Oh look another XSS." Sure enough...
jarland is offline   Reply With Quote
Old 28 Oct 2023, 04:09 PM   #3
Bamb0
Master of the @
 
Join Date: Feb 2005
Location: USA
Posts: 1,873
Isnt is sad Mr Jarland??

Any email server is open to an attack and nothing seems to be able to be done
Bamb0 is offline   Reply With Quote
Old 28 Oct 2023, 10:54 PM   #4
jarland
Essential Contributor
 
Join Date: Apr 2014
Posts: 399

Representative of:
MXRoute.com
Quote:
Originally Posted by Bamb0 View Post
Isnt is sad Mr Jarland??

Any email server is open to an attack and nothing seems to be able to be done
It's been patched. XSS vulnerabilities have their correlations in desktop email clients as well, and the whole concept around attacking someone by this type of vulnerability is a very common one. But this won't be the last XSS vulnerability, always be careful opening shady emails.
jarland is offline   Reply With Quote
Old 29 Oct 2023, 04:50 AM   #5
Bamb0
Master of the @
 
Join Date: Feb 2005
Location: USA
Posts: 1,873
Yea thats how it should be but sadly it wont ever be perfect (1 person might still open one)
Bamb0 is offline   Reply With Quote
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump


All times are GMT +9. The time now is 08:45 AM.

 

Copyright EmailDiscussions.com 1998-2022. All Rights Reserved. Privacy Policy