TA488 Exploits Outlook Half-Click Flaw to Deploy Persistent OWAReaper Backdoor

TA488 has resurfaced with a high‑end half‑click campaign against on‑premises Outlook Web Access (OWA), exploiting CVE‑2026‑42897 to deploy a persistent JavaScript backdoor, OWAReaper, that can survive credential rotation, browser restarts, and full host re‑imaging. The operation exploits CVE‑2026‑42897, a cross‑site scripting flaw in OWA disclosed by Microsoft in May 2026 and confirmed to be actively […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: