Russian spies take their half-click email attack from Zimbra to Outlook

https://image.theregister.com/5237994.jpg?imageId=5237994&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Opening a booby-trapped message unleashes a browser implant that can survive password changes and device rebuilds

The Russian espionage crew that turned simply reading an email into a security risk has expanded beyond Zimbra, with Proofpoint saying it's now pulling the same half-click trick against Microsoft Outlook Web Access.

Proofpoint says the cyber group it tracks as TA488, or "Laundry Bear," began exploiting CVE-2026-42897, a cross-site scripting flaw in the Outlook Web Access (OWA) component of on-premises Exchange Server, a day before researchers and government agencies exposed the group's abuse of a zero-day in Zimbra Collaboration Suite.

Unlike conventional phishing attacks, this one doesn't depend on persuading the victim to follow a link or download a file. If a target opens the booby-trapped message in OWA, the browser executes attacker-controlled JavaScript inside the victim's authenticated mail session. Exchange Online is not affected.

According to Proofpoint, TA488 abused the OWA...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more