TI Mindmap HUB
Threat Intelligence Report

TA488 Targets Zimbra Mailservers with Half-Click Exploits

📅 July 24, 2026 📰 www.proofpoint.com 🔍 1 CVE(s) referenced

Russian-aligned threat actor TA488 exploited a zero-day vulnerability in Zimbra mailservers using stealthy “half-click” email exploits to steal credentials and exfiltrate sensitive emails from Ukrainian and US government and defense targets throughout 2025–2026.

vendor
CVE-2025-66376

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle