When Business Email Compromise Starts Rewriting Reality
CISA KEV means this flaw has been seen exploited in real attacks — not predicted, observed. Treat it as urgent regardless of its score.
- On CISA KEV — actively exploited. Patch immediately.
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the traditional BEC model in unexpected ways. …
- CVE-2024-45519nvd ↗KEVEPSS 100%
- CVE-2025-27915nvd ↗KEVEPSS 4%
- CVE-2026-73570nvd ↗KEVEPSS 32%
- CVE-2022-27925nvd ↗KEVEPSS 99%
- CVE-2022-37042nvd ↗KEVEPSS 92%
- CVE-2023-37580nvd ↗KEVEPSS 47%
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.