July 25, 2026
- Russian Zimbra campaign broadens across webmail platforms. Proofpoint expands the picture on the state-linked actor (TA488 / Void Blizzard / Laundry Bear), tying the "half-click" Zimbra XSS (CVE-2025-66376) to a wider Operation RoundPress push that also weaponized zero-days in mDaemon (CVE-2025-3929) and SOGo (CVE-2026-8496) (earlier coverage). Proofpoint. · Threat Activity
in A Default-Config RCE Cracks GitLab, and the PoC Is Already Public