CISA Cybersecurity Alerts

CISA Alert AA22-228A – Threat actors exploiting multiple CVEs against Zimbra Collaboration suite.


Listen Later

CISA and the Multi-State Information Sharing & Analysis Center, or MS-ISAC are publishing this joint Cybersecurity Advisory in response to active exploitation of multiple Common Vulnerabilities and Exposures against Zimbra Collaboration Suite, an enterprise cloud-hosted collaboration software and email platform.

AA22-228A Alert, Technical Details, and Mitigations

Volexity’s Mass Exploitation of (Un)authenticated Zimbra RCE: CVE-2022-27925

Hackers are actively exploiting password-stealing flaw in Zimbra

CISA adds Zimbra email vulnerability to its exploited vulnerabilities catal…

CVE-2022-27925 detail

Mass exploitation of (un)authenticated Zimbra RCE: CVE-2022-27925

CVE-2022-37042 detail

Authentication bypass in MailboxImportServlet vulnerability

CVE-2022-30333 detail

UnRAR vulnerability exploited in the wild, likely against Zimbra servers

Zimbra Collaboration Kepler 9.0.0 patch 25 GA release

Zimbra UnRAR path traversal

Operation EmailThief: Active exploitation of zero-day XSS vulnerability in…

Hotfix available 5 Feb for zero-day exploit vulnerability in Zimbra 8.8.15

All organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at [email protected] or (888) 282-0870 and to the FBI via your local FBI field office or the FBI’s 24/7 CyWatch at (855) 292-3937 or [email protected].

Learn more about your ad choices. Visit megaphone.fm/adchoices

...more
View all episodesView all episodes
Download on the App Store

CISA Cybersecurity AlertsBy N2K Networks

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

12 ratings


More shows like CISA Cybersecurity Alerts

View all
CyberWire Daily by N2K Networks

CyberWire Daily

1,023 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,047 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

181 Listeners

Hacking Humans by N2K Networks

Hacking Humans

313 Listeners

Talkin' Bout [Infosec] News by Black Hills Information Security

Talkin' Bout [Infosec] News

92 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners