In July 2026, a China-aligned threat actor, TA419, ran credential-phishing campaigns impersonating prominent economists and AI policymakers, including a former White House Office of Science & Technology Policy leader.
More info: https://t.co/oQzUV5EPgF
Threat actors are stealing U.S. university .edu credentials and using them to run job scams, fake scholarships, and other advance-fee fraud scams. We engaged with the fraudsters to learn how they operate. See our blog for our findings and screenshots.https://t.co/G2a1rcLrFU
Our cloud and AI threat research expert Yaniv Miron will share more in an afternoon #Protect26 breakout session.
AI is changing the account takeover playbook. Organizations should ensure all exposed gaps are filled.
Within 90 seconds of compromise, a threat actor triggered multiple post-access sequences. Our threat researchers believe this activity was AI-enabled.
Our new blog examines this active TeamFiltration campaign, tracked as UNK_CondorFiltration. https://t.co/VooTYcXbmJ
The commonality: all were service accounts, still open on the tenant’s ID plane, belonging to no specific person.
Today at #Protect26, Sumit Dhawan shared how attackers can use AI to research targets, mimic trusted behavior, and accelerate lateral movement once they gain access.
On August 28th, China-aligned actor TA412 (aka Violet Typhoon) began delivering a Chrome exploit. Within days, 3️⃣ more state-sponsored clusters adopted the same exploit chain.
Our Discarded podcast features the Proofpoint researchers who tracked it all. https://t.co/bFqCgYMIHt
Proofpoint researchers observed four China-aligned espionage actors using the same Chrome and Windows exploit kit.
@arstechnica covered the activity, which was likely enabled by a patch gap and the hastened pace of AI-based vulnerability discovery. https://t.co/45dhzPyKxq
The observed patch-gap weaponization, use of a privilege escalation exploit targeting older Windows builds, and TTPs observed = an ephemeral capability rushed out ahead of an anticipated patch.
This contrasts starkly w/ the tradecraft usually seen in historical browser exploits.
New research from @Proofpoint: BlueMoon, a Chrome-to-Windows exploit kit, has been used by at least four state-sponsored threat actors since late August. https://t.co/xPsfDXMwpI
Both browser vulns were "patch-gap" zero-days at the time of the observed activity, meaning they had already been fixed in public upstream Chromium source code but remained unpatched in the latest stable releases of Chrome and Chromium-based browsers available to the public.
"Half-click" attacks require the target to simply open or preview an email. No download or link click is needed.
Our @greglesnewich says these attacks deserve their own category, describing a level of subtlety in email-based exploits never before seen. https://t.co/82FUQlc7ia
PackClient consists of:
• 1st-stage loader executable
• 2nd-stage loader (PackClientLauncher) DLL module
• Core module (PackClientCore)
• Several optional plugins that can be downloaded with op command
Full malware analysis in our blog. We also shared detection tips & IOCs.
Proofpoint has observed a Chinese-speaking threat actor (TA4922) using a command and control (C2) framework called PackClient.
The framework enables data theft, surveillance, and downloading of additional plugins and payloads.
Blog: https://t.co/6uBWNjye6Q
#phishing#emailrisk
TA4922 used PackClient to send payloads inside tax-themed lures, impersonating Shandong Provincial Tax Bureau and Government of India Income Tax Dept.
PackClient dropped ManageEngine RMM. We used the Deception Pro malware observability environment to view follow-on payloads.
Join us for the Aug. 26 livestream of Intercepted.
☁️ TOPIC: THE EVOLVING CLOUD THREAT LANDSCAPE ☁️
🎥: https://t.co/YYIDrREIoX
We'll look at how traditional brute-force methodology is evolving and how threat actors are using spoofing techniques to level up their capabilities.
Selena Larson of @Proofpoint presented at @CactusCon 26.
Her hot take: the way we talk about AI is quite muddy. Buzzwords, miscommunication, hype... 🤔
Here, she shares her perspective, helps separate hype from reality, and highlights the real threat. https://t.co/ZLrlNMDORQ