Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: US and European government and critical infrastructure entities
Incident: Exploitation of an XSS vulnerability in Microsoft OWA to maintain persistent mailbox access.
Impact: Unauthorized long-term access to sensitive communications and intelligence data.
Attacker: Laundry Bear (TA488 / Void Blizzard)
Analysis: Laundry Bear is employing ‘half-click’ XSS attacks via CVE-2026-42897, where simply viewing an email triggers the compromise. The attack utilizes generic lures to bypass suspicion, deploying a JavaScript payload that ensures persistence across browser reboots, credential rotations, and full device re-imaging. This reflects a significant increase in the actor’s tradecraft and ability to maintain long-term intelligence access.
Recommendations: Immediately apply security updates for Microsoft OWA to mitigate CVE-2026-42897.; Enhance email security filtering to identify and flag anomalous patterns from Proton Mail or compromised internal addresses.; Audit active sessions and browser environments for unauthorized persistent scripts that may survive credential rotations.
Source: The Hacker News / Proofpoint
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source