🚨 We are following up with additional observations of the TA488’s use of “half-click” exploits.
The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA).
New blog: proofpoint.com/us/blog/threat…
Today we are releasing a pair of reports:
First: a joint release with NSA, FBI, and the allies, on TA488 (Void Blizzard, Laundry Bear) using half-click XSS exploits


