ThreatInsight

@threatinsight.proofpoint.com

Proofpoint's insights on targeted attacks and the cybersecurity threat landscape.

A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering with “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns.

Bild

🚨 We are following up with additional observations of the TA488’s use of “half-click” exploits. The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). New blog: www.proofpoint.com/us/blog/thre...

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US

Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release

proofpoint.com

Saher@saffronsec.bsky.social · 2w ago

Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...

Last year, we warned defenders how FIDO-based authentication can be downgraded via a phishlet to force FIDO to less secure MFA methods, enabling session cookie theft via AiTM phishing. www.proofpoint.com/us/blog/thre... We recently learned that this capability was added to Evilginx Pro.

Don’t Phish-let Me Down: FIDO Authentication Downgrade | Proofpoint US

Key takeaways FIDO-based passkeys remain a highly recommended authentication method to protect against prevalent credential phishing and account takeover (ATO) threats.

proofpoint.com

Researchers at Proofpoint have identified OAuth client ID spoofing emerging as a stealthy account enumeration technique targeting Microsoft Entra ID. Attackers can validate usernames and infer credential validity, all without generating a successful sign-in event. www.proofpoint.com/us/blog/thre...

OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration | Proofpoint US

Key Takeaways Proofpoint has observed OAuth client ID spoofing emerging as a novel technique, increasingly leveraged in cloud campaigns. Microsoft Entra ID returns different responses

proofpoint.com

Proofpoint's threat research team is tracking a password-spraying campaign against the U.S. education sector, using a spoofed user agent so outdated it may predate some of the accounts it targeted. Read more below. 👇🏼🧵

Our new @threatinsight report is a comprehensive overview of TA4922, a newly designated Chinese-speaking, financially motivated threat actor that largely targets East Asia. It currently conducts more unique campaigns than any other cybercriminal we track. www.proofpoint.com/us/blog/thre...

TA4922: The Suspected Chinese Crime Group is Going Global | Proofpoint US

Key Findings: TA4922 is a highly sophisticated threat actor demonstrating a rapid operational tempo and continually evolving malware arsenal. The group has been

proofpoint.com

Device code phishing is exploding, and AiTM actors are getting in on it. We found ODx phishing-as-a-service providing device code capabilities in addition to their AiTM offerings. ODx is one of the most popular AiTM kits currently. It's also tracked as Storm-1167 and FlowerStorm.

After a lull in activity targeting Europe from mid-2023 to mid-2025, the China-aligned espionage actor #TA416 (RedDelta, Vertigo Panda, Red Lich) has resumed targeting European government and diplomatic entities, with a recent expansion to the Middle East. brnw.ch/21x1f0j

I’d come running back to EU again: TA416 resumes European government espionage campaigns | Proofpoint US

Key findings From mid-2025 onwards, the China-aligned threat actor TA416 resumed observed targeting of European government and diplomatic organizations following a period of reduced EU-

brnw.ch

Monetary concerns + federal deadlines + abundance of “time-sensitive” email advertisements. Tax season is a recipe for cybercrime. Proofpoint researchers have seen hundreds of malicious tax-themed campaigns this year. Read the threat brief here: brnw.ch/21x1bsT.

Security brief: tax scams aim to steal funds from taxpayers | Proofpoint US

What happened  Threat actors love to take advantage of tax season. It’s peak social engineering time: combine monetary concerns with often stressful responsibilities, sprinkle in the

proofpoint.com