blackorbird[verified]@blackorbirdExploit
The post lists multiple zero‑day half‑click exploits targeting webmail services (Zimbra, mDaemon, Roundcube, SOGo) with CVE identifiers, but does not provide PoC code, patches, or evidence of active exploitation.
Rıdvan Yağlı[verified]@ridvanyagliActive Exploitation
Red team alerts to active exploitation of Roundcube CVE-2024-42009 and CVE-2025-49113 via email-based chain attacks targeting universities in the US, Canada, and Turkey, urging immediate software updates.
PurpleOps[verified]@PurpleOps_ioActive Exploitation
A China‑aligned group, UNK_MassTraction, is actively exploiting Roundcube webmail CVEs CVE‑2024‑42009 and CVE‑2025‑49113 against U.S. and Canadian universities, specifically targeting physics and engineering research inboxes since May.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
Chinese-linked actors exploit Roundcube XSS CVE‑2024‑42009 to deploy IceCube stealer and then chain CVE‑2025‑49113 to drop SquareShell or VShell backdoors on university mail servers; a patch for Roundcube is now available.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
Chinese‑aligned UNK_MassTraction reportedly targeted U.S. and Canadian university physics and engineering departments using the Roundcube XSS vulnerability CVE‑2024‑42009, indicating active exploitation in the wild.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
Chinese actors are actively exploiting CVE-2024-42009 and CVE-2025-49113 in Roundcube, compromising university mail servers via a single email and installing VShell backdoors and webshells.
ByteSec1401 Efshagari[verified]@Leila97726926Active Exploitation
CVE‑2024‑42009 is being actively exploited by the UNK_MassTraction malware against RoundCube, targeting Canadian and U.S. universities, but no patch or mitigation information is provided.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
China-linked threat actors exploited CVE-2024-42009 and CVE-2025-49113 to compromise Roundcube webmail servers at academic institutions, deploying IceCube stealer and SquareShell webshell for lateral movement and data exfiltration.