www.proofpoint.com/us/blog/t… On 22 July 2026, Russia-aligned threat actor TA488 (also known as Void Blizzard or Laundry Bear) launched a campaign exploiting CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access. The attacks targeted U.S. and European government entities plus organizations in telecommunications, finance, hospitality, and aerospace.
The campaign relies on improved “half-click” exploits that trigger compromise simply by opening the email. It delivers a previously unknown JavaScript browser-based implant called OWAReaper. The implant runs entirely inside the OWA browser context with no host footprint, uses dual C2 channels and dual exfiltration methods, and can persist through browser restarts, credential changes, and full device re-imaging. Infrastructure for the campaign appeared as early as March 2026, raising the possibility that the vulnerability was used as a zero-day before Microsoft’s out-of-band patch.