TA488 exploits OWA cross-site scripting flaw to plant browser implants that survive credential rotation.
US agencies warn that Russian APT group Laundry Bear is actively exploiting CVE-2025-66376 against unpatched Zimbra Collaboration servers worldwide.