Proofpoint has rolled out two new security capabilities in 2026, and separately published detailed research on a Russian espionage campaign that exploited a webmail flaw for months before it was patched. The three developments are often described together, but they happened at different times and rest on different kinds of evidence — a distinction worth understanding before evaluating what any of it means for organizations running Microsoft 365.
The first is Active Exploits Protection, announced May 27, 2026, which the company says is available globally as of that announcement, delivered through its platform and API access. The second is a Core Email Protection API inside Threat Protection Workbench, introduced July 17, 2026, aimed at Microsoft 365 environments. The third is a threat-research report, published July 23, 2026 in coordination with the NSA and FBI, detailing how a Russia-aligned hacking group exploited a Zimbra email server vulnerability as a zero-day for roughly five months in 2025.
Proofpoint has framed all of this as part of a strong second quarter, but the timing is worth clarifying. By the company’s own account, its fiscal second quarter ended in June. The Core Email Protection API announcement and the Zimbra research both came in July — after that quarter closed. Only Active Exploits Protection was announced within the quarter itself.
Table of Contents
What Proofpoint Announced
Active Exploits Protection is designed to help security teams cut through vulnerability overload. Rather than ranking flaws by theoretical severity scores, it uses Proofpoint’s own telemetry — spanning what the company describes as more than 3 million organizations and 14,000 large enterprises — to flag which vulnerabilities are actually being exploited in real attacks. Proofpoint cites a striking figure to justify the approach: fewer than 6% of all disclosed vulnerabilities are ever exploited in the wild, meaning most “critical” alerts a security team receives may not represent an urgent threat at all.
The Core Email Protection API expands what Proofpoint’s Threat Protection Workbench can do for organizations running Microsoft 365. It’s built to combine protection that happens before an email is delivered, protection that happens after delivery, and protection that triggers when a user clicks a link — bringing all three into one system rather than three disconnected tools.
The Zimbra research is a different kind of announcement altogether. It isn’t a product launch — it’s a technical report describing how a threat actor Proofpoint tracks as TA488 (also known by other researchers as Void Blizzard or Laundry Bear) used a previously unknown flaw in Zimbra Collaboration Suite webmail software to spy on government and defense targets.
Why It Matters Now
Proofpoint’s broader argument, echoed across all three announcements, is that artificial intelligence is compressing the time between when a vulnerability is discovered and when it gets weaponized. According to the company, that gap has shrunk from years to a matter of hours in some cases — sometimes even before public vulnerability-tracking databases catch up.
That argument lines up with what happened in the Zimbra campaign: attackers were actively exploiting the flaw before a patch existed and before it appeared in public advisories. Whether or not AI tools specifically accelerated that particular campaign, the case illustrates the underlying problem Proofpoint is selling a solution for — organizations that wait for official severity ratings before acting can fall behind attackers who are already inside their systems.
It’s worth noting that these efficacy claims and timelines come from Proofpoint itself. No independent security firm or analyst has audited or replicated them, so they should be read as the company’s own account of how well its systems perform.
Active Exploits Protection: Features and Availability
According to Proofpoint’s press release, Active Exploits Protection offers four capabilities. It prioritizes vulnerabilities based on confirmed real-world exploitation rather than theoretical risk scores. It claims to convert exploit intelligence into active protection automatically — in about 35 seconds, with that protection spreading across Proofpoint’s network within 18 minutes, according to the company. It provides application programming interface (API) access so security teams can pull that intelligence into their own tools, including security operations center platforms and vulnerability management systems. And it’s designed to plug into automated and AI-driven security workflows rather than requiring manual review of every alert.
Proofpoint states the product is available globally now, not in a limited preview or pilot. Cognizant, a technology services and consulting firm, said in the announcement that it plans to help its own clients put the tool to use through its managed security services — an indication of channel-partner interest, though it isn’t independent testing of the product’s performance.
Core Email Protection API: What’s New in Threat Protection Workbench
The Core Email Protection API adds several specific tools to Threat Protection Workbench. A feature called the Threat Interaction Map is meant to give security analysts an at-a-glance view of what was detected, who was targeted, and how an attack unfolded — instead of requiring them to piece that story together manually. Every flagged message comes with an explanation of why it was flagged, drawing on behavioral patterns, sandbox testing results, and unusual sender-recipient relationships.
The system also looks for signs that a trusted supplier’s email domain has been compromised, and it tries to catch account takeovers by correlating suspicious login activity with signs of email compromise — supporting responses like forcing a password or multi-factor authentication reset. A feature called the Satori Abuse Mailbox Agent is designed to automatically sort through emails that employees report as suspicious, a task that traditionally consumes significant analyst time.
Proofpoint says the API also connects with other security tools organizations may already use, including CrowdStrike, Okta, Palo Alto Networks, and Microsoft Defender for Endpoint, so that identity, endpoint, and email signals can be correlated in one place.
As with Active Exploits Protection, Proofpoint describes this API as “now available.” But unlike the exploit-protection launch, there’s no separate press release spelling out global availability, pricing, or which existing customers get access immediately. The claim comes from a single company blog post, and no independent source — trade press, analyst firm, or customer account — has yet confirmed the rollout’s scope.
The Zimbra Vulnerability and TA488 Attribution
The most detailed and independently verifiable part of this story concerns a vulnerability Proofpoint calls CVE-2025-66376. According to Proofpoint’s research, the threat actor TA488 exploited this flaw in Zimbra Collaboration Suite mailservers starting around July 2025, continuing for at least five months until it was patched.
The attack method is notable because it required almost nothing from the victim. The malicious code was embedded directly in the body of an email, disguised using a technique that split apart pieces of HTML and CSS code so that Zimbra’s built-in filter couldn’t recognize it as a threat. When a target simply opened or previewed the email in a vulnerable version of Zimbra’s webmail client, the hidden code reassembled itself and ran automatically — no link click, no attachment, no further action needed. Security researchers call this a “half-click” exploit.
Once the code executed, malware Proofpoint named ZimReaper went to work: stealing login tokens and saved passwords, harvesting two-factor authentication codes, setting up a hidden password for long-term access to the account, and exporting up to 90 days of a victim’s email history to a remote server. Proofpoint says the campaign targeted Ukrainian government agencies as well as U.S. government, scientific, and defense-industrial organizations.
Here’s where some important nuance gets lost in a quick read of the announcement. The vulnerability itself was not first revealed on July 23, 2026, when Proofpoint published its report. Public vulnerability records show CVE-2025-66376 was already logged around early January 2026, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities catalog in March 2026 — months before Proofpoint’s detailed writeup. Zimbra had also already shipped patches by that point. What Proofpoint published in July wasn’t the discovery of a live, unpatched threat; it was a deep dive into who was behind the earlier attacks and how they worked, released alongside a joint advisory from the NSA and FBI.
That timeline matters because “zero-day” accurately describes what TA488 was doing in 2025 — exploiting a flaw before a fix existed — but it doesn’t mean the flaw was still zero-day, or even new, by the time Proofpoint’s report came out.
Proofpoint is also careful about how confidently it links TA488 to the previously known group Void Blizzard, also called Laundry Bear by some researchers. The company states plainly that its own direct evidence couldn’t confirm that connection with high confidence — it says the link was confirmed through its collaboration with U.S. government partners rather than through independent proof. Outside outlets, including eSecurity Planet, have since reported on the campaign as well, corroborating the broad details of TA488’s activity and the technique used.
How the Three Developments Relate
It’s easy to read Proofpoint’s own framing and assume these are three parts of one coordinated release. They aren’t. Active Exploits Protection and the Core Email Protection API are commercial products with separate announcement dates roughly seven weeks apart. The Zimbra research is threat intelligence — a look backward at an attack campaign, not a new tool customers can buy. The connecting thread is Proofpoint’s broader argument about AI-accelerated attacks, but treating all three as a single “Q2” story overstates how tightly they’re actually linked.
Timeline of Announcements
| Date | Development |
|---|---|
| May 27, 2026 | Active Exploits Protection announced, stated as globally available |
| July 17, 2026 | Core Email Protection API announced as available in Threat Protection Workbench |
| July 23, 2026 | Zimbra/TA488 threat-research report published with NSA and FBI |
Active Exploits Protection vs. Core Email Protection API
| Active Exploits Protection | Core Email Protection API | |
|---|---|---|
| Announced | May 27, 2026 | July 17, 2026 |
| What it does | Prioritizes vulnerabilities based on real-world exploitation | Unifies pre-delivery, post-delivery, and click-time email protection |
| Delivery | Platform capabilities and API access | API integration with Threat Protection Workbench |
| Stated availability | Globally available at launch | “Now available,” per company blog |
| Independent confirmation | Reported by trade press based on company materials | Not yet independently confirmed |
Limitations and Open Questions
Several practical details remain unknown. Proofpoint hasn’t publicly disclosed pricing or licensing terms for either product, nor has it specified whether the Core Email Protection API is rolling out to all Threat Protection Workbench customers at once or in phases. No independent technical documentation — from analysts, reviewers, or customers — currently exists to verify the specific performance figures Proofpoint has published, including its detection-speed and accuracy claims.
Conclusion
Taken individually, these three developments tell a coherent story about where enterprise email security is heading: less reliance on theoretical risk scores, more emphasis on real-world attacker behavior, and growing pressure to unify defenses that have traditionally operated in silos. But readers evaluating Proofpoint’s announcements should keep the details straight rather than absorbing them as one undifferentiated launch. Active Exploits Protection is a generally available product as of late May. The Core Email Protection API is a newer addition whose rollout details are still thin. And the Zimbra research, while genuinely significant as a look at how a state-linked group operated undetected for months, describes a threat that was already identified and patched by the time the public report arrived. What’s worth watching next is whether independent reviewers weigh in on the two new products’ actual performance, and whether Proofpoint or government partners release further findings tying TA488 more concretely to other known threat groups.
FAQ
What is Proofpoint Active Exploits Protection? It’s a security tool that identifies which software vulnerabilities are actually being exploited by attackers, using Proofpoint’s own threat telemetry, and automatically applies protection against those threats rather than relying on general severity ratings.
Is Proofpoint Active Exploits Protection generally available? Yes. Proofpoint’s press release states it became available globally on the day of its May 27, 2026 announcement, delivered through the company’s platform and via API.
What does the Core Email Protection API add to Threat Protection Workbench? It brings together protection before an email is delivered, after it’s delivered, and at the moment a link is clicked, along with tools like the Threat Interaction Map, automated abuse-mailbox review, and detection of compromised suppliers and account takeovers — all for organizations running Microsoft 365.
What is the Zimbra vulnerability TA488 exploited, and is it still active? The flaw, CVE-2025-66376, allowed attackers to run malicious code just by having a victim open or preview an email in a vulnerable Zimbra webmail client. It has since been patched, and it was added to the U.S. government’s Known Exploited Vulnerabilities catalog in March 2026, before Proofpoint’s detailed report was published.
Who is TA488, and how confident is the attribution to Void Blizzard? TA488 is a Russia-aligned hacking group Proofpoint says is likely directed by Russian intelligence. Proofpoint states its own telemetry could not confirm a high-confidence link to the previously known group Void Blizzard on its own, but that the connection was confirmed through collaboration with U.S. government partners.
Did Proofpoint announce all of this in the same quarter? Not exactly. Active Exploits Protection was announced in May, within Proofpoint’s fiscal second quarter as the company defines it. The Core Email Protection API and the Zimbra research were both published in July, after that quarter had already closed.
What organizations were targeted in the Zimbra campaign? Proofpoint says the campaign targeted Ukrainian government entities along with U.S. government, scientific research, and defense-industrial-base organizations.

