SpyPress: JavaScript Malware Used in Operation RoundPress
SpyPress is an obfuscated JavaScript-based malware used by TA458 in Operation RoundPress. It targets webmail platforms including Roundcube, Zimbra, Kerio, SOGo, and…
SpyPress is an obfuscated JavaScript-based malware used by TA458 in Operation RoundPress. It targets webmail platforms including Roundcube, Zimbra, Kerio, SOGo, and…
TA458 is a threat actor tracked by Proofpoint, likely a Russian military intelligence operation. It conducts Operation RoundPress using half-click XSS exploits…
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…
CVE-2025-49113 is a vulnerability in Roundcube's file upload handler that allows unsafe PHP deserialization, used by TA458 to deploy SpyPress backdoors.