2026-07-23 (Back to Inventory) TA488 Targets Zimbra Mailservers with Half-Click Exploits Author(s): Greg Lesnewich , Konstantin Klinger , Mark Kelly , Nick Attfield , Saher Naumaan Organization: Proofpoint js.zimreaper Open article directly Related Articles 2026-07-23 ⋅ Proofpoint ⋅ Greg Lesnewich , Konstantin Klinger , Mark Kelly , Nick Attfield , Saher Naumaan Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 SpyPress 2026-07-07 ⋅ Proofpoint ⋅ Greg Lesnewich , Mark Kelly , Proofpoint Threat Research Team One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation IceCube 2026-06-08 ⋅ Proofpoint ⋅ Carlos Rubio , Saher Naumaan Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency Overlord RAT
The threat actor TA488 is targeting Zimbra mailservers using "half-click" exploits, which require less user interaction than traditional phishing by leveraging zero-day vulnerabilities in the webmail interface.