← All articles

Zimbra: email security also needs visibility into the mail server.

Microsoft’s exploitation report connects a mail-server weakness to host activity and published network indicators.

Incident period: July–August 2026 activity; report dated 30 SeptemberSources checked: 1 Oct 2026
THE POSTURE QUESTION

Treat mail delivery, host execution, and administrative trust as connected investigation surfaces.

What the technical report establishes

Microsoft describes exploitation of CVE-2026-73570 through Zimbra’s SNMP notification path when the optional package and notifications are enabled. Observed compromises included web shells, credential collection, and persistence. The report is dated 30 September; the described activity includes July and August. Microsoft’s investigation.

Security posture: the mail gateway is not the whole control

Editorial assessment: a message can interact with server-side processing before any employee opens it. Investigations need a shared timeline across mail flow, host execution, identity, and network traffic.

Verify the deployed version and optional components against current vendor guidance. If compromise is established, review service and cluster trust with the incident-response team; resetting individual mailbox passwords may leave other administrative access intact. Keep patching and compromise assessment as separate workstreams.

Which teams should act

Team Practical next step
Email security Identify relevant mail servers and preserve mail-processing records; do not assume a user click is required.
IT operations Record versions, optional components, configuration and remediation evidence.
EDR Confirm sensor coverage on Linux mail nodes and investigate process, file and persistence evidence.
SIEM / SOC Correlate host events with DNS, firewall and authentication records across the cluster.
Legal / privacy Establish mailbox and authentication-data exposure from evidence, not merely the presence of the CVE.

Sourced IOC subset

The Microsoft report lists these network leads. They are a subset, not a complete detection strategy: transzimbra[.]linkpc[.]net, psk1zim[.]abrdns[.]com, tls[.]psk1zim[.]abrdns[.]com, wslogzimbra[.]linkpc[.]net, 45.32.30[.]235, and 193.42.40[.]135. Keep the report date and context with imports; do not browse attacker infrastructure.

KQL and Splunk hunt

Illustrative and not executed in a live environment. KQL requires Defender for Endpoint telemetry in DeviceNetworkEvents for the selected server. RemoteUrl must contain a hostname for these exact comparisons. SPL assumes normalized src_ip, dest_ip, dest_port, dest_host, and action fields; verify them against a known network event. Replace every placeholder. Both searches cover seven recent days, not the historical July–August window.

// Defender XDR; replace with the onboarded Zimbra DeviceName.
let MailServer = "REPLACE_WITH_ZIMBRA_DEVICE_NAME";
DeviceNetworkEvents
| where Timestamp >= ago(7d)
| where DeviceName =~ MailServer
| where RemoteIP in ("45.32.30.235", "193.42.40.135")
    or RemoteUrl in~ ("transzimbra.linkpc.net", "psk1zim.abrdns.com",
                     "tls.psk1zim.abrdns.com", "wslogzimbra.linkpc.net")
| project Timestamp, DeviceName, ActionType, RemoteIP, RemotePort, RemoteUrl,
          InitiatingProcessFileName, InitiatingProcessAccountName
| order by Timestamp desc
| take 200

Download KQL

index=YOUR_NETWORK_INDEX src_ip="YOUR_ZIMBRA_IP" earliest=-7d latest=now
| where in(dest_ip, "45.32.30.235", "193.42.40.135")
    OR in(lower(dest_host), "transzimbra.linkpc.net", "psk1zim.abrdns.com",
          "tls.psk1zim.abrdns.com", "wslogzimbra.linkpc.net")
| table _time src_ip dest_ip dest_port dest_host action
| sort -_time
| head 200

Download SPL

A hit can be an attempted or blocked connection, a security test, or traffic to reassigned infrastructure. Inspect process and action context. No match cannot clear the server: coverage gaps, altered infrastructure, URL-form fields, and other attacker behaviors are outside this search. Defender XDR table schema; Splunk evaluation functions.

Reporting note

The Hacker News coverage and the primary report are dated 30 September. Exact publication times were not verified. This is adjacent-date research from the review ending 1 October 2026, 14:42 UTC, not a confirmed rolling-24-hour disclosure. The original activity is older.

All articles →日本語で読む ↗