TA458: Russian Military Intelligence Operation Targeting Webmail
TA458 is a threat actor tracked by Proofpoint, likely a Russian military intelligence operation. It conducts Operation RoundPress using half-click XSS exploits…
TA458 is a threat actor tracked by Proofpoint, likely a Russian military intelligence operation. It conducts Operation RoundPress using half-click XSS exploits…
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
A Russian state-sponsored espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal emails, passwords, and two-factor authentication recovery codes…
ACR Stealer, an infostealer active since 2024, is targeting enterprise networks by stealing saved browser passwords, live session tokens, PDFs, Microsoft 365…
Proofpoint has uncovered a novel evasion technique called OAuth client ID spoofing, exploited by at least two threat actors to validate stolen…
A sophisticated device code phishing campaign targeting Microsoft 365 accounts has been observed between late June and early July 2026, leveraging collaboration-themed…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…
Security researcher Bert-Jan Pals analyzed roughly 3,000 live ClickFix payloads and presented findings at OrangeCon in early June, publishing details on June…
Check Point Research has revealed that threat actors pre-built and staged fraud infrastructure targeting the FIFA World Cup 2026 months before the…
Cybersecurity researchers have uncovered two malicious campaigns linked to North Korean threat actors, exploiting developer tools like Microsoft Visual Studio Code (VS…