
TA488(Void Blizzard、Laundry Bear) Targets Zimbra Mailservers with Half-Click Exploits https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 CVE-2025-27915: Zimbra (zero-day) CVE-2025-3929: mDaemon (zero-day) CVE-2023-43770: Roundcube (n-day) CVE-2024-42009: Roundcube (n-day) CVE-2026- 8496: SOGo (zero-day) https://www.proofpoint.com/us/blog/threat-insight/ta458-roundpress-exploits
Post summary
The text announces that threat actors TA488 and TA458 have identified multiple zero-day and other zero-day‑like vulnerabilities in webmail systems such as Zimbra, mDaemon, Roundcube, and SOGo, with a reference to a Proofpoint blog for additional details.

