IT security researchers have observed attacks by Russian cybercriminals on an Exchange vulnerability. The flaw has been known since May and has already been exploited there. Simply displaying a maliciously prepared email in Outlook Web Access (OWA) is sufficient. Software updates are available to close the security vulnerability.
The IT security company Proofpoint currently reports on this. The security leak stems from insufficient input filtering when generating web pages; it is a cross-site scripting vulnerability. Attackers from the network can perform spoofing attacks without authentication, Microsoft explained. Displaying an email in OWA leads to the execution of embedded JavaScript (CVE-2026-42897, CVSS 8.1, risk “high”).
Targets in the EU and USA in sight
The IT researchers explain that the campaign targets government agencies in the USA and Europe, as well as the telecommunications, finance, hospitality, and aerospace industries. The criminal organization known as TA488, Laundry Bear, or Void Blizzard is increasingly relying on “half-click” exploits, where opening an email is enough to compromise user accounts. They demonstrate significantly improved loading mechanisms, techniques, and malware, indicating a substantial increase in the group's capabilities.










