CISA says Ulej sent stolen data to Flowerbed infrastructure over DNS and HTTPS, with DNS payloads Base32-encoded, split into short labels, and triggered by image requests. Defenders should patch to ZCS 10.1.13 or 10.0.18, avoid Classic webmail until patched, watch for suspicious domains and random subdomains, review localStorage for zd_comp_YYYY-MM-DD, and revoke all Application Passcodes and 2FA scratch keys if compromise is found[10][11][12][13][14][15][16][17][18].
🧵 5/5