This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
ThreatInsight
threatinsight.proofpoint.com
did:plc:5gwujgymmotfb4pszrxoblwb
🚨 We are following up with additional observations of the TA488’s use of “half-click” exploits.
The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA).
New blog: https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit?utm_source=twitter&utm_medium=social_organic
[contains quote post or other embedded content]
2026-07-29T20:34:40.974Z