Three names, three roles, and I mixed them up without realizing it.
Russia-linked APT28 has exploited a high-severity XSS vulnerability in Zimbra in attacks against Ukrainian entities.
Note: this package is not 100% compatible with the CBOR specification. See the Not implemented section for more details.