Russian state-backed hackers have spent the past year targeting employees in the US and NATO countries using an email exploit that steals comms just by having a target open a message, no clicks required.
Our @greglesnewich shared his insights with @CNN.
@Proofpoint's insights on targeted attacks and the security landscape.
Follow us on Bluesky: bsky.app/profile/threat…
Joined August 2013
- A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering w/ “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns.
- 🚨 We are following up with additional observations of the TA488’s use of “half-click” exploits. The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). New blog: proofpoint.com/us/blog/threat…Today we are releasing a pair of reports: First: a joint release with NSA, FBI, and the allies, on TA488 (Void Blizzard, Laundry Bear) using half-click XSS exploits
- Our @proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods being actively developed and sold: proofpoint.com/us/blog/threat….
- Russian state-backed threat actors are compromising organizations using Zimbra mail servers by sending phishing emails that require victims to simply open the message. @greglesnewich of @proofpoint shared his insights on the activity with @DarkReading.


