2026-07-23 (Back to Inventory) Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 Author(s): Greg Lesnewich , Konstantin Klinger , Mark Kelly , Nick Attfield , Saher Naumaan Organization: Proofpoint js.spypress Open article directly Related Articles 2026-07-23 ⋅ Proofpoint ⋅ Greg Lesnewich , Konstantin Klinger , Mark Kelly , Nick Attfield , Saher Naumaan TA488 Targets Zimbra Mailservers with Half-Click Exploits Unidentified JS 007 (Zimbra Stealer) 2026-07-07 ⋅ Proofpoint ⋅ Greg Lesnewich , Mark Kelly , Proofpoint Threat Research Team One Email Closer to the Edge: UNK_MassTraction & the Physics of Exploitation IceCube 2026-06-08 ⋅ Proofpoint ⋅ Carlos Rubio , Saher Naumaan Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency Overlord RAT
The threat actor TA458 is actively exploiting zero-day vulnerabilities in Zimbra webmail servers using "half-click" exploits, which require minimal user interaction to trigger malicious JavaScript payloads. The article does not provide specific CVE identifiers, CVSS scores, affected version ranges, fixed versions, or recommended workarounds for these ongoing attacks.