hacker-news · Crawled Oct 1, 2026
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
6 IoCs 1 CVEs
Read original article ↗
AI Summary
Threat actors are exploiting a patched command injection vulnerability, CVE-2026-73570, in Zimbra Collaboration Suite (ZCS) to achieve remote code execution without authentication. The flaw is triggered via a crafted SMTP request when SNMP notifications are enabled and the zimbra-snmp package is installed. Upon exploitation, attackers deploy JSP web shells, establish reverse shells, escalate privileges, and harvest authentication secrets including LDAP credentials and service account data. They also perform lateral movement using Zimbra's SSH identity and exfiltrate mailbox data, sometimes using cloud tools like AzCopy targeting Azure Blob storage.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 6 extracted
MITRE ATT&CK TTPs 12 techniques
T1003 OS Credential Dumping · Credential Access T1021.001 Remote Desktop Protocol · Lateral Movement T1021.006 Windows Remote Management · Lateral Movement T1053.001 T1053.001 T1059.001 PowerShell · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1081 T1081 T1090 Proxy · Command And Control T1136 Create Account · Persistence T1552 Unsecured Credentials · Credential Access T1566 Phishing · Initial Access