Summary
A Russian cybercrime group, TA488, exploited a zero-day vulnerability in the Zimbra email platform (CVE-2025-66376) to conduct espionage against Western targets, including NATO and Ukrainian government organizations. The 'half-click exploit' allowed attackers to compromise systems simply by victims viewing malicious emails, though the group reportedly vanished after its exposure in February 2026.