CVE Tools

Уязвимости в Roundcube используются для слежки за учеными

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedRoundcube WebmailUNK_MassTraction

Our summary

Researchers at Proofpoint have uncovered a cyber espionage campaign targeting universities in the US and Canada, exploiting vulnerabilities in Roundcube Webmail to monitor scientists and faculty members. The attackers use CVE-2024-42009 (XSS flaw) and CVE-2025-49113 (deserialization bug) to steal login credentials and install malicious web shells like SquareShell and VShell. These tools allow remote code execution and network access, enabling long-term persistence on compromised systems. The threat group, tracked as UNK_MassTraction, is suspected to be linked to China due to infrastructure overlaps and linguistic clues.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store