A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering with “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns.
ThreatInsight
@threatinsight.proofpoint.com
Proofpoint's insights on targeted attacks and the cybersecurity threat landscape.
🚨 We are following up with additional observations of the TA488’s use of “half-click” exploits. The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). New blog: www.proofpoint.com/us/blog/thre...
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
proofpoint.com
Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...
Our Proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods that are being actively developed and sold: www.proofpoint.com/us/blog/thre....
Our researchers discovered that a Russia-aligned threat actor was exploiting a previously unknown (zero-day) vulnerability against Zimbra mailservers. We alerted government partners, with whom we have collaborated on further discovery. Blog: www.proofpoint.com/us/blog/thre...
Last year, we warned defenders how FIDO-based authentication can be downgraded via a phishlet to force FIDO to less secure MFA methods, enabling session cookie theft via AiTM phishing. www.proofpoint.com/us/blog/thre... We recently learned that this capability was added to Evilginx Pro.
Don’t Phish-let Me Down: FIDO Authentication Downgrade | Proofpoint US
Key takeaways FIDO-based passkeys remain a highly recommended authentication method to protect against prevalent credential phishing and account takeover (ATO) threats.
proofpoint.com
The StealC ecosytem #OperationEndgame led to the seizure of more than 25.6M unique creds stolen from +385k compromised sites. Proofpoint was proud to contribute to the operation alongside industry partners. Listen to Discarded for a scoop inside the disruption. www.proofpoint.com/us/podcasts/...
Researchers at Proofpoint are tracking Cruciferra, a crypter service that is used by multiple unrelated threat actors. The self-proclaimed “underground's most lethal crypter” has been observed delivering a wide range of RATs and infostealers. Blog: www.proofpoint.com/us/blog/thre...
Back by popular demand, senior threat researcher Joe Wise will join our next Intercepted livestream on July 22nd. Joe will share real examples of active threat campaigns, malware samples, tips, tricks, and more research for defenders. Register to join us 👉 www.proofpoint.com/uk/resources...
Researchers at Proofpoint have identified OAuth client ID spoofing emerging as a stealthy account enumeration technique targeting Microsoft Entra ID. Attackers can validate usernames and infer credential validity, all without generating a successful sign-in event. www.proofpoint.com/us/blog/thre...
OAuth Client ID Spoofing: Why Fake Client IDs Are Gaining Traction for Stealthy Enumeration | Proofpoint US
Key Takeaways Proofpoint has observed OAuth client ID spoofing emerging as a novel technique, increasingly leveraged in cloud campaigns. Microsoft Entra ID returns different responses
proofpoint.com
Proofpoint's threat research team is tracking a password-spraying campaign against the U.S. education sector, using a spoofed user agent so outdated it may predate some of the accounts it targeted. Read more below. 👇🏼🧵
🚨 New research: Proofpoint has identified a suspected China-aligned espionage cluster, UNK_MassTraction, exploiting multiple Roundcube n-day vulnerabilities to compromise mail servers at U.S. and Canadian universities. Analysis, infection chain & IOCs: www.proofpoint.com/us/blog/thre....
Researchers from Proofpoint have reported an increase in AitM activity originating from #NovaCookies, a suspected variant of the #Sneaky2FA phishing kit.
FIFA FANS ‼️ Cybercriminals are using #FIFAWorldCup excitement to steal your personal info and credit card details. One recent email scam we observed used the subject line: “Congratulations! You're Eligible for the FIFA World Cup 2026 Giveaway” 🧵 1/5
Just announced by @europol.europa.eu: the global #OperationEndgame initiative has disrupted the #StealC ecosystem, a prominent information-stealing malware operation. See our blog for details: www.proofpoint.com/us/blog/thre...
#SocGholish, the “FakeUpdates” web injects framework linked to major ransomware events, has been disrupted by #OperationEndgame. ❌ 100 servers and domains worldwide dismantled ❌ 14,971 websites remediated Learn more: www.proofpoint.com/us/blog/thre.... 🧵⤵️
Proofpoint has proudly been accepted into @europol.europa.eu EC3's Advisory Group on Internet Security (AGIS). www.proofpoint.com/us/blog/corp... We look forward to working even more closely with Europol and the AGIS members to strengthen the security and resilience of Europe's digital ecosystem.
Strengthening Public-Private Collaboration in the Fight Against Cybercrime: Proofpoint Joins Europol EC3’s Advisory Group on Internet Security | Proofpoint US
Cybercrime is a global challenge that demands a global response. Threat actors operate across borders, infrastructure, and jurisdictions, requiring defenders to work together with equal speed,
proofpoint.com
🚨 New threat research: Proofpoint identified a likely North Korea-aligned threat cluster, UNK_DeadDrop, targeting software developers through trusted development platforms and workflows. Read the blog: www.proofpoint.com/us/blog/thre....
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency | Proofpoint US
By Saher Naumaan, Carlos Rubio, and the Proofpoint Threat Research Team Key Findings Between April and May 2026, Proofpoint Threat Research observed a likely North Korean threat actor
proofpoint.com
Our new @threatinsight report is a comprehensive overview of TA4922, a newly designated Chinese-speaking, financially motivated threat actor that largely targets East Asia. It currently conducts more unique campaigns than any other cybercriminal we track. www.proofpoint.com/us/blog/thre...
TA4922: The Suspected Chinese Crime Group is Going Global | Proofpoint US
Key Findings: TA4922 is a highly sophisticated threat actor demonstrating a rapid operational tempo and continually evolving malware arsenal. The group has been
proofpoint.com
Sarah Sabotka, staff threat researcher at Proofpoint, is speaking at #Layer8Conference — the only event dedicated to #OSINT and #socialengineering threats facing businesses today. If you're a security leader, you won't want to miss it! June 5–6 | Boston, MA Event info: layer8conference.com
Device code phishing is exploding across the threat landscape, with new device code phishing tools emerging every week. Our new blog explores why adoption of this technique has surged over the past year. www.proofpoint.com/us/blog/thre... A few key points below. 🧵⤵️
Device code phishing is exploding, and AiTM actors are getting in on it. We found ODx phishing-as-a-service providing device code capabilities in addition to their AiTM offerings. ODx is one of the most popular AiTM kits currently. It's also tracked as Storm-1167 and FlowerStorm.
In a public service announcement, the FBI warned the transportation and logistics industry about a sharp rise in cyber-enabled cargo theft, an attack vector our researchers have been closely tracking since last year. www.ic3.gov/PSA/2026/PSA...
Internet Crime Complaint Center (IC3) | Cyber-Enabled Strategic Cargo Theft Surging
ic3.gov
Our award-winning threat research podcast series, Discarded, is celebrating 100 episodes this week! 🎉 Stream now for a trip down memory lane, a few laughs, and a look ahead to what's next in cybersecurity. Cheers to 100 episodes! 🍾 www.proofpoint.com/us/podcasts/...
Proofpoint baited a cargo/transport industry threat actor into performing its malicious activities in a decoy environment operated by Deception.Pro for 30+ days. What resulted: rare, extended visibility into post-compromise operations, tooling, & decision-making. www.proofpoint.com/us/blog/thre...
Our new Discarded podcast episode explores the stealthy world of backdoors, malware detection, and the “secret signals” threat actors use to stay hidden. Stream now for expert insights on signature development, PCAP analysis, and countering espionage tools. 🎙️ www.proofpoint.com/us/podcasts/...
Have you checked your mailbox rules lately? Proofpoint cloud threat researchers found that approx. 10% of compromised accounts in Q4-2025 had malicious mailbox rules created by threat actors shortly after initial access. Details: www.proofpoint.com/us/blog/thre... Here are some highlights. ⤵️
After a lull in activity targeting Europe from mid-2023 to mid-2025, the China-aligned espionage actor #TA416 (RedDelta, Vertigo Panda, Red Lich) has resumed targeting European government and diplomatic entities, with a recent expansion to the Middle East. brnw.ch/21x1f0j
I’d come running back to EU again: TA416 resumes European government espionage campaigns | Proofpoint US
Key findings From mid-2025 onwards, the China-aligned threat actor TA416 resumed observed targeting of European government and diplomatic organizations following a period of reduced EU-
brnw.ch
Monetary concerns + federal deadlines + abundance of “time-sensitive” email advertisements. Tax season is a recipe for cybercrime. Proofpoint researchers have seen hundreds of malicious tax-themed campaigns this year. Read the threat brief here: brnw.ch/21x1bsT.
Security brief: tax scams aim to steal funds from taxpayers | Proofpoint US
What happened Threat actors love to take advantage of tax season. It’s peak social engineering time: combine monetary concerns with often stressful responsibilities, sprinkle in the
proofpoint.com
Proofpoint has directly observed a targeted email campaign that delivers DarkSword RCE, and we attribute the messages to Russian FSB threat actor TA446 with high confidence. 🧵