← All stories
● Covered by 2 sources · 2 reportsMedium impact

Suspected China-Linked Hackers Target Roundcube Vulnerabilities in U.S. and Canadian Universities

🔄 Updated 85d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • UNK_MassTraction exploits Roundcube vulnerability CVE-2024-42009.
  • Targets U.S. and Canadian university physics and engineering departments.
  • Attacks linked to phishing using compromised and spoofed domains.
  • Threat detected since May 2026; focuses on national security research.

Overview of the Attack

A campaign by a threat group known as UNK_MassTraction exploits vulnerabilities in the Roundcube webmail service used by U.S. and Canadian universities. Specifically, the group targeted departments involved in physics, engineering, and national security-linked research.

Exploitation Tactics

The campaign exploited a critical vulnerability in Roundcube, CVE-2024-42009, using phishing emails sent from compromised accounts or via spoofed domains. This attack initially steals credentials and can deploy additional malware such as a backdoor.

Targeted Universities Identified

The activity, ongoing since May 2026, deliberately focuses on universities with ties to national security research, particularly within the astrophysics, particle physics, and engineering fields. This reflects a strategic interest in sensitive academic environments.

Security Implications

The exploitation threatens confidential data related to national security and scientific advancements, highlighting the necessity for improved cybersecurity practices in academic institutions. Deploying hardened access controls and updating software could mitigate such vulnerabilities.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A China-linked threat group, UNK_MassTraction, has exploited vulnerabilities in Roundcube servers at U.S. and Canadian universities to steal credentials and deploy malware. This targeted campaign highlights vulnerabilities in academic environments, particularly in physics and engineering, and could facilitate sensitive information theft related to national security research.

China-aligned hackers exploited critical vulnerabilities in Roundcube to access U.S. and Canadian university email systems. This tactic highlights risks for institutions linked to national security and advanced scientific research, as the attackers utilize phishing and XSS exploits to siphon credentials.