Russian hacking group seen exploiting Roundcube webmail zero-day

Winter Vivern group targets European governments and think tanks

clock • 2 min read
Russian hacking group seen exploiting Roundcube webmail zero-day
Image:

Russian hacking group seen exploiting Roundcube webmail zero-day

ESET researchers have revealed that the Winter Vivern Russian hacking group has exploited a zero-day vulnerability in Roundcube Webmail, targeting various European government entities and think tanks.

This exploitation, which is thought to have begun on 11th October, continued until the security flaw, dubbed CVE-2023-5631, was addressed by the Roundcube development team on 16th October, followin...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
Microsoft warns of Russian hackers targeting vulnerable Outlook email accounts

Threats and Risks

Uses a vulnerability that was patched in March

clock 05 December 2023 • 2 min read
Microsoft’s Patch Tuesday fixes five zero-days

Threats and Risks

Plus three Critical flaws

clock 15 November 2023 • 2 min read
Three zero-days addressed in October 2023 Patch Tuesday

Threats and Risks

'Critical' rating assigned to twelve bugs

clock 11 October 2023 • 3 min read
Upcoming events

Sign up to our newsletter

The best news, stories, features and photos from the day in one perfectly formed email.

More on Threats and Risks

UK accuses Russia of cyber interference targeting election and democracy

UK accuses Russia of cyber interference targeting elections and democracy

The government has imposed sanctions on two Russian nationals for their involvement in spearphishing operations

clock 08 December 2023 • 3 min read
Microsoft warns of Russian hackers targeting vulnerable Outlook email accounts

Microsoft warns of Russian hackers targeting vulnerable Outlook email accounts

Uses a vulnerability that was patched in March

John Leonard
clock 05 December 2023 • 2 min read
Microsoft warns of new ransomware campaign by the Twisted Spider group

Microsoft warns of new ransomware campaign by Twisted Spider group

Uses malvertising to spread Danbot Trojan, then Cactus ransomware

John Leonard
clock 01 December 2023 • 2 min read