Zero-Day Hijinks: Zimbra’s ICS Vulnerability Exploited by Sneaky Calendar Hackers
Zimbra’s zero-day vulnerability had threat actors sending ICS calendar invites you definitely don’t want to RSVP to. Exploiting CVE-2025-27915, attackers used these invites to sneak JavaScript onto systems. While Zimbra patched things up, hackers spoofed the Libyan Navy, targeting Brazilian military orgs. Who knew calendars could be so dangerous?

Hot Take:
Looks like hackers have found a new way to ruin your day—by crashing your calendar party! This time, they gate-crashed using some sneaky ICS files and a Zimbra vulnerability. Guess it’s time to RSVP ‘no’ to any suspicious calendar invites!
Key Points:
- Researchers discovered zero-day attacks exploiting a vulnerability in Zimbra Collaboration Suite (ZCS).
- The flaw, tracked as CVE-2025-27915, allowed attackers to execute arbitrary JavaScript.
- Malicious ICS files were used to steal data from Zimbra Webmail.
- The attack was traced back to the beginning of January, prior to the release of a patch.
- StrikeReady suspects possible Russian involvement but couldn’t confirm it.
Already a member? Log in here