CVE Tools

Hackers exploit Roundcube flaw to spy on academic researchers

BleepingComputerBy Bill Toulas

Reported exploitedRoundcubeUNK_MassTraction

Our summary

A China-linked threat group has been exploiting vulnerabilities in Roundcube webmail servers at U.S. and Canadian universities to steal login details and install backdoor malware. The attackers, tracked as UNK_MassTraction, have focused on institutions conducting research in physics, engineering, and national security. They use a cross-site scripting flaw (CVE-2024-42009) to deliver a credential-stealing payload named IceCube, followed by additional exploits like CVE-2025-49113 to gain deeper access. Security experts recommend applying the latest patches from Roundcube to mitigate these risks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store