Ryan Kalember

@kalember.bsky.social

CSO @ Proofpoint. Infosec lifer. Charter member of nerd nation. MacKenzie appreciator. Forza Inter.

So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US

Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release

proofpoint.com

Last year, we warned defenders how FIDO-based authentication can be downgraded via a phishlet to force FIDO to less secure MFA methods, enabling session cookie theft via AiTM phishing. www.proofpoint.com/us/blog/thre... We recently learned that this capability was added to Evilginx Pro.

Don’t Phish-let Me Down: FIDO Authentication Downgrade | Proofpoint US

Key takeaways FIDO-based passkeys remain a highly recommended authentication method to protect against prevalent credential phishing and account takeover (ATO) threats.

proofpoint.com

New: Microsoft was compromised to deliver malware to users of AI coding agents like Claude and Gemini. In response, Microsoft took the highly unusual step of shutting down dozens and dozens of its own GitHub repos. The malware would steal login credentials from users www.404media.co/microsoft-ha...

Microsoft Hacked to Deliver Malware to Claude and Gemini Users

Microsoft took the highly unusual step of shutting down more than 70 of its own GitHub repositories after hackers pushed malware that would steal credentials from AI coding agent users.

404media.co

In addition to espionage threat actors, financially motivated cybercriminals have been exploiting the WinRAR vulnerability CVE-2025-8088. The highly effective ecrime actor, typically seen distributing Koi Stealer/Koi Loader (TA4561), was observed doing so in Fall 2025. Details. ⤵️

This time of year, threat actors are attempting to send you gifts you’d rather not receive. 🎁 Proofpoint is seeing an increase in holiday-themed threats. Main #phishing lure themes include party invitations, holiday vouchers, end-of-year bonuses, and holiday travel.

New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...

Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US

Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report.  Key findings  Between June and August 2025,

proofpoint.com

TA585 is the identifier of the most recent threat actor named by Proofpoint. The sophisticated cybercriminal, notably, appears to own its entire attack chain with multiple delivery techniques. Learn about TA585 and one of its favored payloads, MonsterV2: brnw.ch/21wWAAU.

When the monster bytes: tracking TA585 and its arsenal | Proofpoint US

Key findings  TA585 is a sophisticated cybercriminal threat actor recently named by Proofpoint. It operates its entire attack chain from infrastructure to email delivery to malware

brnw.ch

Feds have seized infrastructure and charged 16 members of a hacker group based in Russia that allegedly sold access to the DanaBot malware, used in everything from cybercrime like bank fraud and ransomware to espionage and DDOS attacks against Ukraine. www.wired.com/story/us-cha...

Feds Charge 16 Russians Allegedly Tied to Botnets Used in Ransomware, Cyberattacks, and Spying

A new US indictment against a group of Russian nationals offers a clear example of how, authorities say, a single malware operation can enable both criminal and state-sponsored hacking.

wired.com

Proofpoint has published a report detailing new activity from #TA397 (AKA Bitter), a prominent South Asian advanced persistent threat (APT) group. The campaign, which took place in November 2024, targeted a defense sector organization in Turkey. Read the blog: ow.ly/z81o50UshPt.

Hidden in Plain Sight: TA397’s New Attack Chain Delivers Espionage RATs | Proofpoint US

Key findings  Proofpoint observed advanced persistent threat (APT) TA397 targeting a Turkish defense sector organization with a lure about public infrastructure projects in Madagascar.   The attack...

ow.ly

We just launched our new website... please let us know if your RSS feeds or podcatchers are doing anything weird! Meanwhile, check out the new risky.biz website. You can get everything there -- written content, podcasts/audio and video as well. A nice website! And it only took me 18 years!