US, UK warn of Russian APT29 hackers targeting Zimbra, TeamCity servers

Teilen:

U.S. and U.K. cyber agencies warned today that APT29 hackers linked to Russia’s Foreign Intelligence Service (SVR) target vulnerable Zimbra and JetBrains TeamCity servers “at a mass scale.”

A joint advisory issued by the NSA, the FBI, the U.S. Cyber Command’s Cyber National Mission Force (CNMF), and the U.K.’s NCSC warns network defenders to patch exposed servers to block these ongoing attacks.

The four cyber agencies said the hacking group targets unpatched Zimbra and TeamCity servers exposed online “at a mass scale to target victims worldwide across a variety of sectors ” using CVE-2022-27924 and CVE-2023-42793 exploits.

CVE-2022-27924 has been exploited since at least August 2022 to steal email account credentials from unpatched Zimbra Collaboration instances, while CVE-2023-42793 was exploited by both ransomware gangs and North Korean hacking groups for initial access and attempted supply-chain attacks.

“Based on the SVR cyber actors’ TTPs and previous targeting, the authoring agencies assess they have the capability and interest to exploit additional CVEs for initial access, remote code execution, and privilege escalation,” they added.

The advisory lists two dozen vulnerabilities disclosed and fixed over the last six years and asks defenders to deploy security patches and apply mitigations to prevent security breaches.

Also tracked as Cozy Bear, Midnight Blizzard (formerly Nobelium), and the Dukes, this SVR hacking group has been targeting government and private organizations across the United States and Europe for years.

The NSA, FBI, and CISA issued a similar advisory more than three years ago, in April 2021, after the APT29 hackers breached multiple U.S. federal agencies following the SolarWinds supply-chain attack they orchestrated.

They also hacked into NATO nations’ Microsoft 365 accounts to steal foreign policy-related data and breached the Exchange Online accounts of Microsoft executives and other companies in November 2023.

More recently, the Five Eyes (FVEY) intelligence alliance warned in February that APT29 had also started targeting potential victims’ cloud services.

“This activity is a global threat to the government and private sectors and requires thorough review of security controls, including prioritizing patches and keeping software up to date,” said NSA Cybersecurity Director Dave Luber.

“Our updated guidance will help network defenders detect these intrusions and ensure they are taking steps to secure their systems.”

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:45 pm, Juni 22, 2025
Wetter-Symbol 25°C
L: 24° | H: 27°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 50 %
Druck: 1013 mb
Wind: 15 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
24° | 27°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 25°°C 0 mm 0% 15 mph 50 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 17 mph 48 % 1013 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,100.65
-1.16%
Ethereum(ETH)
€1,974.49
-6.90%
Fesseln(USDT)
€0.87
0.01%
XRP(XRP)
€1.76
-5.08%
Solana(SOL)
€115.64
-6.42%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.135139
-4.90%
Shiba Inu(SHIB)
€0.000010
-4.88%
Pepe(PEPE)
€0.000008
-8.67%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen