TI Mindmap HUB
Threat Intelligence Report

Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458

๐Ÿ“… July 26, 2026 ๐Ÿ“ฐ www.proofpoint.com ๐Ÿ” 6 CVE(s) referenced

Russian-aligned threat actor TA458 is aggressively exploiting "half-click" zero-day vulnerabilities in government webmail platforms across Eastern Europe, enabling espionage operations that compromise sensitive email data simply by having targets open malicious messages.

vendor
CVE-2025-3929, CVE-2025-27915, CVE-2026-8496, CVE-2024-42009, CVE-2023-43770, CVE-2025-49113

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle