Skip to content

TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch

Cybersecuritynews Tushar Subhra Dutta July 30, 2026

TA488 has been linked to a new campaign that turns a routine Outlook Web Access email into a gateway for mailbox compromise. The operation abused a now-patched cross-site scripting flaw, tracked as CVE-2026-42897, and could run malicious code when a recipient opened a message in the webmail interface. The campaign targeted government bodies and organizations […]

Extracted Entities

APT Groups (1)

Attack Types (1)

Industries (1)

Platforms (1)