Story perspectives
Data Theft Hits Brazil's Military Amid Zimbra Exploit
10/6/2025
47 6
1 of 1
Story summary
- Zimbra Collaboration Suite CVE-2025-27915 was exploited against Brazil's military, enabling data theft via stored XSS in weaponized iCalendar files.
- StrikeReady first reported the flaw.
- Attackers stole credentials and emails.
- Zimbra released patches on January 27, 2025, but exploitation preceded the fix.
- Oracle E-Business Suite CVE-2025-61882 enables remote code execution without authentication; organizations should apply patches and monitor for IOCs.
