Saher

@saffronsec.bsky.social

Espionage Threat Research @ Proofpoint. Former @virtualroutes.bsky.social fellow. @warstudieskcl.bsky.social alum. She/her

So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well... We kinda lied Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper www.proofpoint.com/us/blog/thre...

Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US

Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release

proofpoint.com

@snlyngaas.bsky.social covers Proofpoint and NSA reporting on Russian actors' exploitation of Zimbra, Roundcube, and other mailservers, to target government, defense, and high science organizations for intelligence collection www.cnn.com/2026/07/23/p...

New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors | CNN Politics

A group of Russian hackers has spent the last year targeting nuclear scientists, defense contractors, and government employees in a cyber-espionage campaign, according to private-sector researchers an...

cnn.com

Saher@saffronsec.bsky.social · 2w ago

Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...

Read Reuters coverage from @raphae.li on Proofpoint and NSA's reporting of half-click exploits used by Russian actors to target Zimbra, Roundcube, and other mailservers to steal emails www.reuters.com/legal/govern...

US and allies say Russian hackers stole emails without social engineering

The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of ​the Zimbra email program without having to fool them into opening ‌an attachmen...

reuters.com

Saher@saffronsec.bsky.social · 2w ago

Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard www.proofpoint.com/us/blog/thre...

New Iran drop from me tracking an attribution nightmare - UNK_SmudgedSerpent! A little Charming, a little Muddy, and a lot C5. Targeting policy experts with benign conversation starters, health-themed infra, OnlyOffice spoofs, and RMMs. Check out the full story www.proofpoint.com/us/blog/thre...

Crossed wires: a case study of Iranian espionage and attribution | Proofpoint US

Proofpoint would like to thank Josh Miller for his initial research on UNK_SmudgedSerpent and contribution to this report.  Key findings  Between June and August 2025,

proofpoint.com

New DISCARDED podcast drop! Join @greg-l.bsky.social and me as we talk about our fave North Korean groups, DPRK as the neglected child, TA406 and the Russian connection, and finally, the dreaded but pervasive IT worker problem podcasts.apple.com/us/podcast/c... open.spotify.com/episode/01d1...

Comic Sans and Cybercrime: Inside North Korea’s Global Cyber Playbook

Podcast Episode · DISCARDED: Tales From the Threat Research Trenches · 07/01/2025 · 53m

podcasts.apple.com

Fun crossover blog about TA829 (RomCom) & TransferLoader with my ecrime pals @selenalarson.bsky.social it’s got it all: 🛰️ Popped routers for sending phish 📊 ACH on attribution 👾 custom protocols 👽 cool malware 🕵️ crime 🎯 espionage ❔many unanswered questions www.proofpoint.com/us/blog/thre...

10 Things I Hate About Attribution: RomCom vs. TransferLoader | Proofpoint US

Threat Research would like to acknowledge and thank the Paranoids, Spur, and Pim Trouerbach for their collaboration to identify, track, and disrupt this activity.  Key takeaways

proofpoint.com

My first blog with Proofpoint is live! And we love a good crossover. State-sponsored actors try their hand at ClickFix - the hottest thing in cybercrime. Meet the North Koreans, Iranians, and Russians who are upping their social engineering game www.proofpoint.com/us/blog/thre...

Around the World in 90 Days: State-Sponsored Actors Try ClickFix | Proofpoint US

Key Findings While primarily a technique affiliated with cybercriminal actors, Proofpoint researchers discovered state-sponsored actors in multiple campaigns using the ClickFix social

proofpoint.com