Roundcube Community Forum

News and Announcements => General Discussion => Topic started by: dutterman on March 18, 2026, 12:39:34 PM

Title: Security concerns - Uncovering an APT28 Roundcube Toolkit
Post by: dutterman on March 18, 2026, 12:39:34 PM
Hello,

I'm running RC since probably a decade and really happy with the UI. But I wonder what I can do to increase security.
After reading: https://hunt.io/blog/operation-roundish-apt28-roundcube-exploitation it seems that even using the 2-factor authentication plugin, the webapp is vulnerable to exploits.

Is there any guidance on how to increase security to mitigate these risks?