Skip to content

Body: HTML @import tag-splitting XSS — RoundPress/ZimReaper webmail exploit delivery - #4981

Open
yana-ivanov wants to merge 4 commits into
sublime-security:mainfrom
yana-ivanov:yana-ivanov/roundpress-html-import-tagsplitting-xss
Open

Body: HTML @import tag-splitting XSS — RoundPress/ZimReaper webmail exploit delivery#4981
yana-ivanov wants to merge 4 commits into
sublime-security:mainfrom
yana-ivanov:yana-ivanov/roundpress-html-import-tagsplitting-xss

Conversation

@yana-ivanov

Copy link
Copy Markdown
Contributor

Description

Detects emails containing the @import tag-splitting obfuscation technique used by TA458 (Operation RoundPress/SpyPress) and TA488 (Void Blizzard/ZimReaper) to deliver cross-site scripting exploits against self-hosted webmail platforms including Zimbra, Roundcube, mDaemon, SOGo, and Kerio.

Opening the email in a vulnerable webmail client is sufficient to trigger execution — no link click or attachment required (half-click exploit). Active campaigns disclosed jointly by Proofpoint, NSA, and FBI on July 23, 2026.

Coverage gap: body_cve_2023_5631.yml covers a specific Roundcube CVE signature. This rule targets the generic @import tag-splitting obfuscation technique and known ZimReaper payload markers across all targeted platforms.

Associated samples

@yana-ivanov
yana-ivanov requested a review from a team July 29, 2026 22:00
@yana-ivanov
yana-ivanov requested a review from a team as a code owner July 29, 2026 22:00
@github-actions github-actions Bot added review-needed Indicates that a PR is waiting for review shared-samples:excluded:author_membership labels Jul 29, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Shared Samples Sync - Action Required

This PR was not automatically synced to shared-samples because the author is not a member of the sublime-security organization.

To enable syncing, an organization member can comment /update-shared-samples on this PR.

Once triggered, the rules will be synced on the next scheduled run (every 10 minutes).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant