Bottom line: An Exchange vulnerability (CVE-2026-42897) enables TA488 to achieve mailbox takeover merely by viewing emails, establishes server-level persistence, and evades conventional detection methods.
The Russia-aligned group TA488 has exploited a security flaw in Microsoft Exchange to inject a browser-based backdoor through nothing more than viewing crafted emails in Outlook Web Access. The attack requires no user interaction and targets authorities and enterprises in multiple critical sectors.
The campaign by TA488 (also known as Void Blizzard and Laundry Bear) began on 22 July and exploited CVE-2026-42897 – a cross-site scripting vulnerability in Exchange’s email HTML processing. Viewing a crafted message in Outlook Web Access triggers the execution of malicious JavaScript in the browser without requiring the user to click a link or open an attachment.
Affected are Exchange Server 2016 and 2019 as well as the Subscription Edition; Exchange Online is not vulnerable. Microsoft disclosed the flaw on 14 May, distributed an emergency mitigation, and followed with a code fix in June. Security infrastructure for the campaign was established in March – before Microsoft’s disclosure – indicating possible zero-day exploitation. The attacks targeted government organisations in the US and Europe as well as enterprises in telecommunications, finance, hospitality, and aerospace and defence.
Source: www.csoonline.com · Published 30 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.