{"id":1196429,"date":"2023-10-25T18:21:49","date_gmt":"2023-10-25T22:21:49","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1196429"},"modified":"2023-10-25T18:21:49","modified_gmt":"2023-10-25T22:21:49","slug":"pro-russia-hackers-target-inboxes-with-0-day-in-webmail-app-used-by-millions","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1196429","title":{"rendered":"Pro-Russia hackers target inboxes with 0-day in webmail app used by millions"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2023\/10\/system-hacked-800x450-1.jpg\" alt=\"Pro-Russia hackers target inboxes with 0-day in webmail app used by millions\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2023\/05\/system-hacked.jpg\" class=\"enlarge-link\" data-height=\"563\" data-width=\"1000\">Enlarge<\/a> (credit: Getty Images)<\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>A relentless team of pro-Russia hackers has been exploiting a zero-day vulnerability in widely used webmail software in attacks targeting governmental entities and a think tank, all in Europe, researchers from security firm ESET said on Wednesday.<\/p>\n<p>The previously unknown vulnerability resulted from a critical cross-site scripting error in Roundcube, a server application used by <a href=\"https:\/\/roundcube.net\/about\/\">more than 1,000 webmail services<\/a> and millions of their end users. Members of a pro-Russia and Belarus hacking group tracked as Winter Vivern used the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Cross-site_scripting\">XSS bug<\/a> to inject JavaScript into the Roundcube server application. The injection was triggered simply by viewing a malicious email, which caused the server to send emails from selected targets to a server controlled by the threat actor.<\/p>\n<h2>No manual interaction required<\/h2>\n<p>\u201cIn summary, by sending a specially crafted email message, attackers are able to load arbitrary JavaScript code in the context of the Roundcube user\u2019s browser window,\u201d ESET researcher Matthieu Faou <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/winter-vivern-exploits-zero-day-vulnerability-roundcube-webmail-servers\/\">wrote<\/a>. \u201cNo manual interaction other than viewing the message in a web browser is required.\u201d<\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1978806#p3\">Read 7 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1978806&amp;comments=1\">Comments<\/a><\/p>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1978806\" target=\"_blank\" rel=\"noopener\">Pro-Russia hackers target inboxes with 0-day in webmail app used by millions<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Getty Images) A relentless team of pro-Russia hackers has been exploiting a zero-day vulnerability in widely used webmail software in attacks targeting governmental entities and a think tank, all in Europe, researchers from security firm ESET said on &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1196429\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1196430,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-1196429","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1196429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1196429"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1196429\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/1196430"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1196429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1196429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1196429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}