TA488 Exploits Outlook Half
TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent JavaScript backdoor, OWAReaper, that can survive credential rotation, browser restarts, and full host re‑imaging. The operation exploits CVE‑2026‑42897, a cross‑site scripting flaw in OWA disclosed by Microsoft in May 2026 and confirmed to be actively […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
