Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit

Reported 29 Jul 2026 by otx · Severity: medium

TA488, a Russia-aligned threat actor, initiated a campaign on July 22, 2026, exploiting CVE-2026-42897, a cross-site scripting vulnerability in Outlook Web Access. The campaign targeted US and European government entities, along with telecommunications, financial, hospitality, an