6/6/2025, 10:16:56 AM | CyberSecurityNews | news

    Hackers Exploiting Roundcube Vulnerability to Steal User Credentials

    A sophisticated spear phishing campaign targeting Polish organizations exploited the CVE-2024-42009 vulnerability in Roundcube webmail systems, enabling credential theft via a Service Worker-based attack. The threat group UNC1151, linked to Belarusian and Russian intelligence, used social engineering tactics to compromise users. A new Roundcube vulnerability (CVE-2025-49113) was also identified, though not yet exploited.

    Read more on CyberSecurityNews