LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host

roundcube

roundcubehigh

MassTraction Exploits Roundcube Flaws at US, Canadian Universities

A threat group known as UNK_MassTraction, believed to be linked to China, is exploiting vulnerabilities in Roundcube webmail to gain unauthorized access to sensitive research mail servers at universities in the United States and Canada. The attackers are reportedly stealing user sessions to achieve this access.

roundcubehigh

Suspected Chinese Threat Group Targets Universities via Vulnerable Roundcube Servers

A sophisticated threat group, believed to be operating from China, is actively exploiting security weaknesses in Roundcube webmail servers. Their objective is to gain unauthorized access to university networks across the United States and Canada, with the ultimate goal of stealing user login information.

CVE-2024-42009high

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

Researchers have identified a new cyberattack campaign targeting academic institutions in North America. The attackers, believed to be linked to China, are exploiting vulnerabilities within the Roundcube webmail system used by physics and engineering departments.

CVE-2024-42009high

Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities

A China-aligned espionage group has been observed targeting U.S. and Canadian universities, specifically in physics and engineering departments. The attackers exploited two vulnerabilities in the Roundcube email client (CVE-2024-42009 and CVE-2025-49113) to steal credentials and establish persistent access through webshells and backdoors. Proofpoint researchers identified the campaign, which appears to be ongoing, and noted that victims may not yet be aware of the compromise.