Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities
China-aligned hackers exploited critical flaws in Roundcube webmail to target physics and engineering departments at U.S. and Canadian universities. The attack leveraged CVE-2024-42009 to steal credentials.
Universities must prioritize patching and monitoring email systems, especially in high-value research sectors. Consider deploying threat intelligence tools to detect anomalous access patterns tied to compromised credentials.
A China-aligned threat actor targeted university departments specializing in physics and engineering using vulnerabilities in Roundcube webmail. The campaign focused on credential theft to potentially access sensitive research data.
The attackers exploited CVE-2024-42009, a critical flaw with a CVSS score of 9.3, which has since been patched. Institutions using Roundcube are urged to verify patch status and strengthen their email defenses.
This incident highlights the ongoing targeting of academia by state-sponsored groups, particularly in sectors linked to intellectual property and advanced research. Enhanced monitoring and rapid response strategies are essential to mitigate such threats.