Over three million POP3 and IMAP without TLS encryption are currently exposed to the Internet and vulnerable to sniffing attacks.
See also: Kimsuky hacking gang steals credentials with Russian emails

IMAP and POP3 are two methods for accessing email on mail servers. IMAP is recommended for checking email from multiple devices, such as phones and laptops, because it keeps your messages on the server and synchronizes them between devices. POP3, on the other hand, downloads emails from the server, making them accessible only on the device they were received from.
The TLS secure communication protocol helps keep secure when exchanging and accessing their emails over the Internet through client/server applications. However, when TLS encryption is not enabled, the contents and credentials of their messages are sent in clear text, exposing them to network eavesdropping attacks.
As scans from security threat monitoring platform ShadowServer, approximately 3.3 million hosts are running POP3/IMAP services without TLS encryption enabled and are exposing usernames and passwords in plain text when transmitted over the Internet.
See also: Vulnerabilities in Mailcow Server are exploited by hackers!
ShadowServer notifies mail server operators that their POP3/IMAP servers do not have TLS enabled, exposing users' unencrypted usernames and passwords to sniffing attacks.

The original TLS 1.0 specification and its successor, TLS 1.1 , have been in use for nearly two decades, with TLS 1.0 introduced in 1999 and TLS 1.1 in 2006. After extensive discussions and the development of 28 draft protocols, the Internet Engineering Task Force (IETF) approved TLS 1.3 , the next major version of the TLS protocol, in March 2018.
In a coordinated announcement in October 2018, Microsoft ,, Google, Apple and Mozilla said they would retire the insecure TLS 1.0 and TLS 1.1 protocols in the first half of 2020. Microsoft began enabling TLS 1.3 by default in the latest Windows 10 Insider builds starting in August 2020.
In January 2021, the NSA also provided guidance on identifying and replacing outdated TLS protocol versions and configurations with modern, secure alternatives.
See also: Operation Texonto: Russian hackers target Ukrainians with emails about the war
Sniffing attacks are one of the most common ways to compromise mail server security. This method involves monitoring and intercepting data transmitted over a network, such as passwords, personal information, and other sensitive information. Attackers use special tools, known as sniffers, to collect the data without the user's permission or knowledge. Sniffing attacks are particularly dangerous on unsecured or open networks, necessitating the use of technologies such as encryption and secure protocols to protect the data.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
