A Russian state-backed campaign against Zimbra webmail went straight for 2FA backup codes, not passwords. Here is why that part of MFA gets ignored, and what to do about it.
Tag:
Zimbra
-
-
Google’s Threat Analysis Group found a critical Zimbra XSS vulnerability in the Classic Web Client that lets a crafted email hijack a live session. Zimbra has patched it in version …