Hackers now exploit critical Roundcube flaw in code injection attacks
Hackers exploit Roundcube flaw, Canadian Cyber Security warns of active exploitation.
Intelligence analysis by Qwen 2.5 (3B)

Hacked Roundcube Webmail instances are being actively exploited, with Canadian Cyber Security urging admins to secure their servers.
Hackers found a way to trick Roundcube, a popular email program, into letting them do bad things. They can now pretend to be a regular user and steal data without being caught.
Analysis
{"heading_1":"Background on Roundcube and the Vulnerability","content_1":"The vulnerability has been targeted by both cybercrime and state-sponsored hacking groups, including the Winter Vivern and APT28 groups.","content_2":"In February, CISA flagged two other Roundcube flaws as actively exploited, ordering government agencies to secure their networks within three weeks.","heading_2":"Active Exploitation and Impact","heading_3":"Historical Context and Similar Exploits","content_3":"Since May 2022, CISA has tagged 11 Roundcube Webmail vulnerabilities as exploited in the wild."}
Key points
- Roundcube Webmail instances are being actively exploited by hackers.
- The vulnerability involves a pre-authenticated SQL injection in the virtuser_query plugin.
- The Canadian Cyber Security recommended disabling or removing the virtuser_query plugin to eliminate the attack vector.
- Since May 2022, CISA has tagged 11 Roundcube Webmail vulnerabilities as exploited in the wild.
By patching the vulnerability, Roundcube can prevent the bad guys from using it to steal data.
If the vulnerability is not patched, hackers might continue to exploit it, causing more data theft.


