Russian cyber espionage group TA488 has exploited a cross-site scripting vulnerability (CVE-2026-42897) in Microsoft Outlook Web Access (OWA) to maintain persistent mailbox access even after credential changes. The implanted JavaScript malware, dubbed OWAReaper, operates stealthily within the OWA browser context, harvesting credentials, stealing OAuth tokens, and surviving device re-imaging by leveraging server-side persistence on Exchange servers and hidden offline cache elements. This advanced half-click exploit campaign targets various sectors including government and finance, enabling the actor to maintain long-term access that cannot be removed by credential rotation alone.
https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html

