1. X
  2. Threat Insight
Log inSign up
Threat Insight
4,330 posts
Image
user avatar
Threat Insight
@threatinsight
@Proofpoint's insights on targeted attacks and the security landscape. Follow us on Bluesky: bsky.app/profile/threat…
proofpoint.com/us/blog/threat…
Joined August 2013
215
Following
12K
Followers
RepliesRepliesMediaMedia
  • user avatar
    Threat Insight
    @threatinsight
    Aug 4
    Russian state-backed hackers have spent the past year targeting employees in the US and NATO countries using an email exploit that steals comms just by having a target open a message, no clicks required. Our @greglesnewich shared his insights with @CNN.
    Image
    New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense...
    From cnn.com
  • user avatar
    Threat Insight
    @threatinsight
    Aug 3
    A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering w/ “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns.
    Image
  • user avatar
    Threat Insight
    @threatinsight
    Jul 29
    🚨 We are following up with additional observations of the TA488’s use of “half-click” exploits. The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). New blog: proofpoint.com/us/blog/threat…
    user avatar
    Greg Lesnewich
    @greglesnewich
    Jul 23
    Today we are releasing a pair of reports: First: a joint release with NSA, FBI, and the allies, on TA488 (Void Blizzard, Laundry Bear) using half-click XSS exploits
    Image
    Image
    Image
  • user avatar
    Threat Insight
    @threatinsight
    Jul 28
    Our @proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods being actively developed and sold: proofpoint.com/us/blog/threat….
    Image
    GIF
  • user avatar
    Threat Insight
    @threatinsight
    Jul 24
    Russian state-backed threat actors are compromising organizations using Zimbra mail servers by sending phishing emails that require victims to simply open the message. @greglesnewich of @proofpoint shared his insights on the activity with @DarkReading.
    Image
    darkreading.com
    Russian Hackers Exploit Zimbra 0-Day Against US, Ukraine Targets
    A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement