💻
Russian cyber campaign infected victims just by viewing an email
💻 Technology

Russian cyber campaign infected victims just by viewing an email

Russian state-sponsored group TA488 exploited a zero-day vulnerability (CVE-2025-66376) in the Zimbra email platform for at least a year, targeting NATO, Ukrainian government and defence entities. Dubbed a "half-click exploit" by Proofpoint, the attack required no action from victims beyond simply viewing a malicious email. The group went dark after Proofpoint publicly exposed the campaign in February 2026.

Comments

No comments yet