LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
CVE-2024-42009high

Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities

A China-aligned espionage group has been observed targeting U.S. and Canadian universities, specifically in physics and engineering departments. The attackers exploited two vulnerabilities in the Roundcube email client (CVE-2024-42009 and CVE-2025-49113) to steal credentials and establish persistent access through webshells and backdoors. Proofpoint researchers identified the campaign, which appears to be ongoing, and noted that victims may not yet be aware of the compromise.

zeroday.news ·

China-aligned attackers have targeted U.S. and Canadian universities, exploiting a chain of vulnerabilities in the Roundcube webmail client to gain unauthorized access to sensitive data and establish persistent footholds within academic networks. The campaign, observed by Proofpoint researchers since May, appears to be ongoing and has primarily focused on physics and engineering departments, with a particular interest in administrators and professors linked to national security or involved in astrophysics and particle physics research.

Proofpoint identified less than ten university victims and estimates that a few dozen institutions may have been compromised. Researchers believe many affected organizations are likely unaware of the intrusion. The attackers leveraged two critical vulnerabilities in Roundcube, an open-source email client, in sequence. The first exploit, identified as CVE-2024-42009, allowed for the execution of JavaScript within a victim's browser. This was followed by the exploitation of CVE-2025-49113, which provided attackers with access to the mail server itself.

The initial point of compromise in this campaign involved a victim simply opening an email. Attackers reportedly used generic lures to prompt this action, initiating the exploit chain. Proofpoint attributes the campaign to a China-aligned threat cluster, designated UNK_MassTraction, due to the use of a known covert network associated with multiple China-aligned groups, an infection chain that ultimately leads to VShell, and the presence of Chinese language artifacts within the phishing emails.

While the attackers' specific objectives remain unclear, the targeting of physics and engineering departments aligns with China's strategic initiatives. Proofpoint researchers have not yet obtained data indicating what specific information may have been exfiltrated, as their observation focused on the initial email delivery and exploitation attempts.

This campaign represents a shift in tactics for China-aligned adversaries, who have historically targeted edge devices like routers and VPN concentrators for network access. Instead of using email for credential harvesting or malware delivery to end-users, this operation utilizes email to compromise the mail server directly, establishing a more foundational presence within the target network.

The exploitation of Roundcube vulnerabilities highlights the ongoing threat posed by compromised webmail clients, which can serve as a critical entry point for sophisticated attackers. The focus on academic institutions involved in sensitive research underscores the persistent interest of nation-state actors in acquiring advanced technological knowledge and data.

Proofpoint's findings come shortly after Google threat hunters reported a separate Chinese state-sponsored espionage group that had maintained a long-term presence within various sectors, including academia, medicine, and defense, for years. The ongoing nature of these campaigns suggests a sustained effort by China-aligned groups to gather intelligence and potentially disrupt research and development in targeted countries.

Further details on the specific impact or data stolen are not yet available, and the investigation into the full scope of the campaign is ongoing. Organizations using Roundcube are advised to ensure their systems are updated to the latest secure versions and to implement robust email security practices.

espionageuniversityroundcubevulnerabilitychina
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

vulnerability

ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 Countries

ToxicPanda 2.0 targets 349 financial apps and abuses Android Wireless Debugging to gain deeper device access and steal banking credentials. ToxicPanda used to be a Europe-focused nuisance targeting a manageable list of banks. That version is gone. Zimperium’s zLabs team just documented ToxicPanda 2.0, and the numbers alone tell the story: 349 targeted financial institutions […]

ai

If you're not using AI to attack your own systems, your adversaries will

Agents are also the new attack surface - cue defenders' existential angst

privacy

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

TikTok has agreed to a $400 million settlement with the U.S. Department of Justice to resolve a lawsuit alleging violations of child privacy laws. The lawsuit, filed in 2024, accused the company of improperly collecting data from users under 13 and failing to comply with parental requests to delete accounts. The settlement includes an immediate payment of $300 million and an additional $100 million contingent on the dissolution of a prior consent decree related to Musical.ly.

malware

Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]

security

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]