www.proofpoint.com/us/blog/thre...
www.proofpoint.com/us/blog/thre...
Well...
We kinda lied
Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper
www.proofpoint.com/us/blog/thre...
Well...
We kinda lied
Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper
www.proofpoint.com/us/blog/thre...
The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA).
New blog: www.proofpoint.com/us/blog/thre...
The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA).
New blog: www.proofpoint.com/us/blog/thre...
www.proofpoint.com/us/blog/thre...
www.proofpoint.com/us/blog/thre...
#TA488 #OWAReaper #OutlookVulnerability #Cybersecurity #EmailThreat
#TA488 #OWAReaper #OutlookVulnerability #Cybersecurity #EmailThreat
Listen/Read: hackread.com/russian-hack...
#CyberSecurity #Zimbra #0day #Vulnerability #Russia #TA488
Listen/Read: hackread.com/russian-hack...
#CyberSecurity #Zimbra #0day #Vulnerability #Russia #TA488
⚠️ Organizations should review and audit their Exchange permissions and revoke tokens for affected add-ins.
⚠️ Organizations should review and audit their Exchange permissions and revoke tokens for affected add-ins.
allowing long-term surveillance of corporate email inboxes. This is part of a broader campaign by TA488 to maintain persistent access to enterprise email systems.
Source: https://securityonline.bsky.social
## 8. Notable Data Breaches: Werth Wealth, Rectory
allowing long-term surveillance of corporate email inboxes. This is part of a broader campaign by TA488 to maintain persistent access to enterprise email systems.
Source: https://securityonline.bsky.social
## 8. Notable Data Breaches: Werth Wealth, Rectory
Cet article constitue une analyse technique approfondie de la vulnérabilité CVE-2026-42897 et de la campagne d'exploitation associée…
🟢 vérification factuelle haute
#ExchangeOWA #OWAReaper #Cyberveille
Cet article constitue une analyse technique approfondie de la vulnérabilité CVE-2026-42897 et de la campagne d'exploitation associée…
🟢 vérification factuelle haute
#ExchangeOWA #OWAReaper #Cyberveille
ロシア系攻撃グループTA488がZimbraメールサーバーを標的に、Half-Click Exploitを悪用して認証情報とメールの窃取を行う攻撃を展開。ユーザーの操作を最小限に抑えた巧妙な手法で、攻撃の変遷や通信方法、インフラ特徴が確認されました。
#標的型攻撃 #情報セキュリティ
Synacorが提供するコラボレーションツール「Zimbra Collaboration Suite(ZCS)」の脆弱性が、国家が関与すると見られる攻撃グループのゼロデイ攻撃で悪用されていたことがわかった。メールを表示するだけで、過去のメールが窃取される状態だった。
...
ロシア政府の支援を受けていると見られ、「Void Blizzard」「CL-STA-1114」「TA488(旧UNK_PitStop)」などとしても追跡されている攻撃グループ「LAUNDRY BEAR」が、当時明らかとなっていなかった脆弱性「CVE-20...
Synacorが提供するコラボレーションツール「Zimbra Collaboration Suite(ZCS)」の脆弱性が、国家が関与すると見られる攻撃グループのゼロデイ攻撃で悪用されていたことがわかった。メールを表示するだけで、過去のメールが窃取される状態だった。
...
ロシア政府の支援を受けていると見られ、「Void Blizzard」「CL-STA-1114」「TA488(旧UNK_PitStop)」などとしても追跡されている攻撃グループ「LAUNDRY BEAR」が、当時明らかとなっていなかった脆弱性「CVE-20...
Discover how an advanced threat actor exploits an Outlook Web Access flaw to deploy the OWReaper mail implant to compromise enterprise communications.
Read the full threat analysis: www.ampcuscyber.com/shadowopsint...
Discover how an advanced threat actor exploits an Outlook Web Access flaw to deploy the OWReaper mail implant to compromise enterprise communications.
Read the full threat analysis: www.ampcuscyber.com/shadowopsint...