
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
A Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails.
The campaign began on July 22 and was conducted by TA488, which is also tracked as Void Blizzard and Laundry Bear, according to a report from the cybersecurity firm Proofpoint.
The attacks targeted government organizations in the US and Europe, as well as companies in the telecommunications, financial, hospitality, and aerospace sectors. Proofpoint did not name the targeted organizations or say how many attacks resulted in successful compromises.
The attackers exploited CVE-2026-42897, a cross-site scrip...