All CosmicBytez Labs articles tagged #Email Security, across news, security advisories, how-to guides, and projects.
Dovecot's Sieve editheader extension has a critical use-after-free (CVSS 9.1) letting authenticated users corrupt memory during mail delivery.
Unauthenticated OS command injection in Green-Computing's NUMail lets remote attackers run arbitrary commands on the mail server. CVSS 9.8.
Zimbra Collaboration Suite contains a critical unauthenticated OS command injection flaw allowing RCE as the Zimbra user via crafted SMTP requests.
CVE-2026-73570, a CVSS 8.9 command injection flaw in Zimbra Collaboration, is actively exploited in the wild for unauthenticated RCE via SNMP.
PortSwigger researcher Gareth Heyes demonstrated at Black Hat USA 2026 that CSS and HTML within emails can escape message boundaries to capture typed passwords, steal session tokens, and leak IP addresses across Outlook, Gmail, Yahoo, Proton Mail, Fastmail, and AOL Mail.
Russia-backed Laundry Bear (Void Blizzard/TA488) exploited CVE-2025-66376 — a stored XSS flaw in Zimbra's Classic UI — to compromise US, Ukrainian, and NATO targets. The 'half-click' attack triggers just by opening an email, bypasses MFA, and plants a persistent backdoor credential.
AegisAI has closed a $36 million funding round led by Battery Ventures, Accel, and Foundation Capital, bringing the company's total raise to $49 million...
AegisAI has closed a $36M Series A, bringing total funding to $49M, to scale its AI agent-based email security platform purpose-built to counter the rise...
A Russian state-sponsored espionage group spent months silently reading Western mailboxes through a zero-click XSS flaw in Zimbra's webmail client —...
A critical stored XSS vulnerability in Zimbra's Classic Web Client allows attackers to deliver specially crafted emails that execute arbitrary code within...
CVE-2025-27915, a stored XSS vulnerability in Zimbra's Classic Web Client, was exploited as a zero-day before public disclosure. Attackers used malicious...
A cyberattack on a major Japanese telecommunications provider compromised an email management system affecting five ISPs, exposing the accounts, webmail...
Japanese telecom giant KDDI Corporation disclosed a data breach affecting up to 14.22 million email accounts across six ISPs — including Nifty, Biglobe,...
Critical security vulnerabilities in SEPPMail Secure E-Mail Gateway — an enterprise email security appliance — could allow attackers to achieve remote...
Microsoft has shared mitigations for CVE-2026-42897 until a permanent patch can be released for affected Exchange Server versions actively being targeted...
Microsoft shared mitigations for a high-severity Exchange Server vulnerability being actively exploited that allows threat actors to execute arbitrary...
Exim has released security updates to patch a severe vulnerability affecting GnuTLS-compiled builds of the world's most widely deployed mail transfer...
A critical unauthenticated vulnerability in Plunk, the open-source AWS SES email platform, allows attackers to forge Amazon SNS webhook payloads without...
CISA has confirmed that a cross-site scripting vulnerability in Zimbra Collaboration Suite is being actively exploited in the wild, with over 10,000...
Step-by-step guide to implementing SPF, DKIM, and DMARC on your domain — eliminate email spoofing, prevent phishing, and gain full visibility into who...
A server-side request forgery vulnerability in Exchange Server is being chained with deserialization flaws for unauthenticated remote code execution....
Secure your Exchange Online environment with mail flow rules, anti-spam policies, DMARC enforcement, admin audit controls, and mailbox permission hardening.