This week, ESET research described how the Winter Vivern APT group has been exploiting a zero-day XSS vulnerability in Roundcube Webmail servers to target European governmental entities and a think tank. ESET researchers uncovered the attacks on October 11 while monitoring Winter Vivern's cyberespionage operations, which typically take aim at governments in Europe and Central Asia. They promptly reported the security loophole to the Roundcube team on October 12, who released security updates for the vulnerability four days later.
The security flaw, assigned CVE-2023-5631, can be exploited via specially crafted email messages. Organizations are strongly recommended to update their installations of Roundcube Webmail to the latest version post-haste.
Connecting With Us
---------------------------------------------------
Our Main Site: https://www.eset.com/int/
X: / eset
Instagram / eset
Facebook / eset
LinkedIn / eset
TikTok / eset_global
WeLiveSecurity blog https://www.welivesecurity.com/
Corporate Blog https://www.eset.com/us/about/newsroo...
YouTube: / esetglobal