Google finds and helps patch a Zimbra Collaboration email server zero-day used to steal data from governments in Greece, Moldova, Tunisia, Vietnam, and Pakistan
It links the attacks to past Chinese APT activity, but does not formally attribute the attacks. — It also points out that Winter Vivern (suspected Belarus) also exploited this after a patch was released. — https://blog.google/... X: Eric Geller / @ericgeller : New: Some national governments failed to patch a flaw in their Zimbra email servers, and multiple hacking groups pounced. Google spotted hackers breaching agencies in Greece, Moldova, Tunisia, Vietnam and Pakistan, most after fixes were available. https://themessenger.com/... [image] Maddie Stone / @maddiestone : 🪲 New blog from me, @_clem1, and Kristen on the Zimbra in-the-wild 0-day, CVE-2023-37580, discovered by TAG in the summer. We discovered 4 different campaigns using the bug against organizations in Greece, Moldova, Tunisia, Vietnam, and Pakistan. https://blog.google/...
Context & Ripple Effects
Google's Threat Analysis Group had already been surfacing actively exploited flaws across widely used software, including a Chrome zero-day tied to a commercial spyware vendor and a WinRAR issue used by government-backed groups. The Zimbra case extends that pattern beyond browsers and desktop tools to government email infrastructure.
The immediate patch did not end the risk: the record notes Winter Vivern exploited the flaw after a fix was available, and later coverage of another actively exploited Zimbra server vulnerability suggests email-server patching remains a recurring exposure point.
First-order effects
- Zimbra administrators, particularly in affected government environments, must apply the CVE-2023-37580 fix and assess whether email data was accessed before remediation.
- Google TAG's discovery and coordination with Zimbra turn an active intrusion path into a patch-and-response exercise, while the reported activity remains linked to prior Chinese APT operations rather than formally attributed.
Second-order effects
- The post-patch exploitation highlights that publishing a fix shifts the security burden to operators; organizations with slower update cycles remain attractive targets for multiple groups.
- Government email operators may face stronger pressure to tighten vulnerability triage, monitoring, and incident-response processes around externally exposed collaboration servers.
Third-order effects
- If repeated Zimbra incidents persist, enterprise email and collaboration infrastructure will be treated less as routine IT plumbing and more as a high-priority intelligence access point requiring rapid, continuous remediation.
- The case reinforces a broader asymmetry in zero-day defense: vendor fixes can close a flaw quickly, but protection depends on whether every deployed server is updated and checked for prior compromise.
The trend: State-focused intrusion activity is increasingly exploiting the gap between vulnerability disclosure and patch deployment in high-value, internet-facing collaboration systems.