daily cyber × ai intelligence

index

tagged

[CVE-2026-42897]

1 edition · 1 item

July 30, 2026

  • TA488 (Laundry Bear / Void Blizzard) is exploiting an Outlook Web Access XSS zero-day (CVE-2026-42897) for persistent mailbox access (earlier coverage). Proofpoint says the Russia-aligned actor began the campaign on July 22, targeting US and European government, telecom, financial, hospitality and aerospace orgs, and is doubling down on "half-click" exploits where merely opening the email triggers compromise. Proofpoint, The Record · Threat Activity

in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius