Skip to content

Company

Proofpoint

Proofpoint is a cybersecurity company providing email security and threat intelligence to protect organizations from phishing and malware.

Known aliases

  • proofpoint.com
  • Proofpoint Inc.
  • Proofpoint Threat Research
  • Proofpoint US

Current stories

buildOne report1 publisher

Fewer than half of the 1,000 most popular websites reject spoofed email

Just 474 of the 1,000 most popular websites set DMARC to reject spoofed mail, a dev.to survey of their DNS found. Thirty-two months after Google and Yahoo began requiring DMARC from bulk senders, 84.5% of the sites publish a record, but only 69.4% apply an enforcing policy to all their mail.

Publishers:dev.to

Reality

Evidence62
Adoption68
Hype gap0
Incentives
Insufficient
Confidence60
securityConfirmed7 publishers

TA419 courts AI policy experts before phishing their cloud accounts

Proofpoint says China-aligned TA419 has posed as a former White House official and an Anthropic employee to phish AI policy experts since at least April 2025. The first approach asks for nothing; the credential-stealing link follows only after a target replies.

Perspective Coverage

7 publishers
Builder
Builder 28%
Operator
Operator 59%
Investor
Investor 13%

Reality

Evidence62
Adoption
Insufficient
Hype gap+20
Incentives30
Confidence65
securityConfirmed7 publishers

Star Blizzard now sends its Ukraine lures from hacked WordPress and cPanel sites

Microsoft says Star Blizzard has sent fake event invitations to more than 100 organizations since January, many from hacked WordPress and cPanel sites. The group, long known for stealing email passwords, now uses the messages to install a Windows backdoor.

Perspective Coverage

8 publishers
Builder
Builder 28%
Operator
Operator 62%
Investor
Investor 10%

Reality

Evidence66
Adoption35
Hype gap+18
Incentives35
Confidence70
productConfirmed3 publishers

China-aligned TA419 lured AI policy experts with fake advisory invitations in officials' names

Proofpoint says China-aligned TA419 posed as two former US officials and an Anthropic employee to phish AI policy experts' Microsoft accounts. Two recipients flagged the Parker emails by checking with her through another channel, a habit teams fielding advisory requests can adopt.

Perspective Coverage

3 publishers
Builder
Builder 20%
Operator
Operator 53%
Investor
Investor 27%

Reality

Evidence58
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence62
buildOne report1 publisher

Star Blizzard now delivers the CosmicPulse backdoor through fake event invitations

Microsoft says Russia's FSB-linked Star Blizzard sent fake event invitations to more than 100 organizations since January 2026. The lures pose as Chatham House and Atlantic Council events and carry a new Python backdoor, CosmicPulse, aimed at people working on Ukraine.

Publishers:dev.to

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence62
securityConfirmed4 publishers

Canada's Cyber Centre flags live attacks on a pre-login Roundcube SQL injection

Canada's Cyber Centre says attackers are exploiting CVE-2026-48842, a no-login SQL injection in Roundcube's virtuser_query plugin rated 8.1. Only unpatched servers running that plugin are exposed, and Shadowserver flags 10 vulnerable hosts out of more than 523,000 online.

Perspective Coverage

4 publishers
Builder
Builder 25%
Operator
Operator 70%
Investor
Investor 5%

Reality

Evidence55
Adoption30
Hype gap+25
Incentives
Insufficient
Confidence60
securityConfirmed9 publishers

Four espionage crews, most China-linked, ran the same Chrome exploit kit through a four-week patch gap

Proofpoint says at least four China-linked espionage groups fired the same BlueMoon code at different victims during the four weeks a Chromium fix took to reach stable Chrome, and two more groups probably did too.

Perspective Coverage

9 publishers
Builder
Builder 31%
Operator
Operator 60%
Investor
Investor 9%

Reality

Evidence80
Adoption30
Hype gap+10
Incentives40
Confidence76
securityConfirmed4 publishers

Rapuncel ships a Microsoft-attested kernel driver built to terminate 145 security products

LastPass traced a fake Authenticator hosted on GitHub to a months-long impersonation campaign that spoofed at least 40 organizations, including its own brand. The server steering victims to the download was still being updated in September.

Perspective Coverage

4 publishers
Builder
Builder 27%
Operator
Operator 64%
Investor
Investor 9%

Reality

Evidence68
Adoption
Insufficient
Hype gap+15
Incentives40
Confidence70
securityOne report1 publisher

Password spraying across more than 5,700 Chilean M365 accounts broke into only seven unused service accounts

Proofpoint says an unknown actor sprayed over 5,700 M365 accounts in Chile and breached only seven, all dormant service accounts at one retailer. Employee logins held, and those seven unused accounts still gave the attacker mail, Teams chats, OneDrive files and, in one case, the Azure portal.

Publishers:darkreading.com

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives55
Confidence50

Earlier coverage

  1. Okta puts an enforcement point between AI agents and the tools they call

    Product · September 22, 2026 · One report1 publisher

  2. Crosspoint pays about 30 times run rate to lead MIND's $72M Series B

    Invest · September 19, 2026 · Confirmed3 publishers

  3. Microsoft rates a missing authentication check in Azure AI Foundry at CVSS 10.0

    Security · September 18, 2026 · One report1 publisher

  4. A third bypass of the same Defender flaw landed hours after Microsoft's second fix shipped

    Build · September 15, 2026 · Confirmed2 publishers

  5. Espionage crews exploited a Chrome flaw that Chromium had already fixed in public source

    Leadership · September 15, 2026 · One report1 publisher

  6. Four espionage crews picked up the same Chrome and Windows exploit chain within days

    Product · September 11, 2026 · One report1 publisher

  7. Proofpoint absorbs Acuvity to see which AI services staff and machines are calling

    Security · September 11, 2026 · One report1 publisher

  8. AI governance lands on 79% of CISOs without a matching increase in resources

    Security · September 9, 2026 · One report1 publisher

  9. Cloudflare turns OpenAI's cyber model into WAF rules that wait on human approval

    Product · September 3, 2026 · One report1 publisher

  10. NovaCookies: $320 a month buys a session-theft rig that rides real Docusign mail

    Security · August 26, 2026 · Confirmed2 publishers