Proofpoint says a China-aligned crew is breaching US and Canadian university mailboxes via Roundcube flaws to steal physics and defence research.

Proofpoint says UNK_MassTraction exploited patched Roundcube flaws to target U.S. and Canadian university mail servers.

A China-linked threat cluster has been exploiting vulnerable Roundcube servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware.

Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'

Proofpoint says a China-aligned crew is breaching US and Canadian university mailboxes via Roundcube flaws to steal physics and defence research.