Hackers have exploited a critical cross-site scripting (XSS) vulnerability in Roundcube webmail, CVE-2024-37383, to steal login credentials. Despite being patched earlier this year, the exploit targeted unpatched systems using deceptive emails with hidden JavaScript code. This incident highlights the risks associated with outdated software and emphasizes the need for timely updates and proactive cybersecurity measures.