Opening a booby trapped message unleashes a browser implant that can survive password changes and device rebuilds The Russian espionage crew that turned simply reading an email into a security risk has expanded beyond Zimbra, with Proofpoint saying it now pulling the same half click trick against Microsoft Outlook Web Access. Proofpoint says the cyber group it tracks as TA488, or Laundry Bear, began exploiting CVE 2026 42897, a cross site scripting flaw in the Outlook Web Access OWA component...

Read the full article at The Register