Oct. 27, 2023, 12:33 p.m. | ESET

ESET www.youtube.com

This week, ESET research described how the Winter Vivern APT group has been exploiting a zero-day XSS vulnerability in Roundcube Webmail servers to target European governmental entities and a think tank. ESET researchers uncovered the attacks on October 11 while monitoring Winter Vivern's cyberespionage operations, which typically take aim at governments in Europe and Central Asia. They promptly reported the security loophole to the Roundcube team on October 12, who released security updates for the vulnerability four days later.

The …

aim apt attacks cyberespionage entities eset eset research exploiting monitoring october operations research researchers roundcube roundcube webmail security servers tank target uncovered vulnerability webmail week week in security winter winter vivern xss zero-day

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)