1. X
  2. Threat Insight
Log inSign up
Threat Insight
4,323 posts
Image
user avatar
Threat Insight
@threatinsight
@Proofpoint's insights on targeted attacks and the security landscape. Follow us on Bluesky: bsky.app/profile/threat…
proofpoint.com/us/blog/threat…
Joined August 2013
215
Following
11.9K
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • user avatar
    Threat Insight
    @threatinsight
    Jul 29
    🚨 We are following up with additional observations of the TA488’s use of “half-click” exploits. The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). New blog: proofpoint.com/us/blog/threat…
    user avatar
    Greg Lesnewich
    @greglesnewich
    Jul 23
    Today we are releasing a pair of reports: First: a joint release with NSA, FBI, and the allies, on TA488 (Void Blizzard, Laundry Bear) using half-click XSS exploits
    Image
    Image
    Image
    1.5K
  • user avatar
    Threat Insight
    @threatinsight
    Jul 28
    Our @proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods being actively developed and sold: proofpoint.com/us/blog/threat….
    Image
    GIF
    1.3K
  • user avatar
    Threat Insight
    @threatinsight
    Jul 24
    Russian state-backed threat actors are compromising organizations using Zimbra mail servers by sending phishing emails that require victims to simply open the message. @greglesnewich of @proofpoint shared his insights on the activity with @DarkReading.
    Image
    darkreading.com
    Russian Hackers Exploit Zimbra 0-Day Against US, Ukraine Targets
    A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.
    1.2K
  • user avatar
    Threat Insight
    @threatinsight
    Jul 23
    Our researchers discovered that a Russia-aligned threat actor was exploiting a previously unknown (zero-day) vulnerability against Zimbra mailservers. We alerted gov't partners, with whom we have collaborated on further discovery. @NSACyber @FBI Blog: proofpoint.com/us/blog/threat….
    Image
    00:00
    2.1K
  • user avatar
    Threat Insight
    @threatinsight
    Jul 22
    The StealC ecosytem #OperationEndgame led to the seizure of more than 25.6M unique creds stolen from over 385k compromised sites. @proofpoint was proud to contribute to the operation alongside industry partners. Listen for a scoop inside the disruption. proofpoint.com/us/podcasts/di…
    Image
    1.4K
  • See @threatinsight's full profile

    Sign up
    Log in
Advertisement
Advertisement