A suspected China-aligned cluster is tied to Roundcube exploitation, showing how a browser-side XSS bug can become a gateway into university mail infrastructure.
A patched webmail flaw keeps resurfacing in academic environments, where one crafted message can turn a browser tab into a credential-stealing foothold.