Black & White Path
Jul 31, 2026 · Information Security
Outlook Zero‑Day Attack: Opening an Email Triggers Execution via OWA HTML Mis‑handling
TA488’s recent campaign exploits CVE‑2026‑42897, a stored XSS in Outlook Web Access that runs malicious JavaScript simply by opening an email, delivering the OWAReaper browser backdoor with multi‑layer persistence, credential theft, and data exfiltration via GitHub, CDN and DNS tunnels.
C2CVE-2026-42897Credential Theft
0 likes · 13 min read
