Ta426 is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed July 23, 2026; most recent activity July 23, 2026.
Russian threat actors TA488 and TA458 are exploiting vulnerabilities in webmail servers, specifically targeting Ukrainian entities and government sectors. TA488 utilizes a half-click exploit via CVE-2025-66376 in Zimbra…