Back to news

Russian Spies Hit Zimbra Zero-Day; LG Cracks Down on Smart TV Proxy Abuse

Two separate security disclosures highlight how attackers exploit trusted platforms—enterprise webmail and consumer smart TVs—to silently harvest data or hijack network resources.

Russian Spies Hit Zimbra Zero-Day; LG Cracks Down on Smart TV Proxy Abuse

What happened

A Russian state-sponsored espionage group leveraged a previously unknown vulnerability in Zimbra's webmail client to silently infiltrate organizational inboxes across Western targets for several months. The exploit required only that a recipient open a malicious message—no further interaction was needed—triggering a payload that exfiltrated up to 90 days of email, the full internal address book, browser-saved passwords, and stored two-factor authentication recovery codes. The NSA, CISA, and allied agencies issued a joint advisory covering the campaign. Separately, LG Electronics USA announced plans to remove smart TV applications from its webOS store that secretly enlist users' televisions as residential proxy nodes, routing third-party internet traffic through home networks without owner knowledge. Researchers had found that more than 42 percent of apps in the store enabled this behavior.

Why it matters for your business

The Zimbra campaign demonstrates that a single unopened-but-received email can compromise an entire communication infrastructure, including the 2FA safeguards organizations depend on as a last line of defense. Enterprises running Zimbra deployments should apply available patches immediately and audit mail gateway logs for anomalous export activity covering the past several months. The LG smart TV issue carries a less obvious but real corporate risk: any company-issued or office-connected smart TV using the LG webOS platform may have been acting as an unauthorized proxy endpoint, potentially exposing network topology and consuming bandwidth in ways that evade standard security monitoring. Organizations should audit which consumer devices share network segments with sensitive systems and consider VLAN isolation as a baseline control.

What to watch next

Attribution details and the full victim list from the Zimbra campaign are expected to emerge as allied agencies continue their joint investigation, which could widen the scope of affected sectors beyond early disclosures. On the smart TV front, LG's enforcement timeline and whether other connected-device manufacturers face similar scrutiny from researchers or regulators will signal how seriously the industry intends to police third-party app ecosystems. Both incidents point toward a broader regulatory push to hold platform owners accountable for security gaps in software they distribute.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp