← Back to feed
general Help Net Security

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Help Net Security Microsoft

Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Mic...

1 IOC
Read the full story Help Net Security →

Related Coverage

general ShinyHunters claims attack on FBI exposes almost all agents Cyberscoop · Sep 22 general BigCommerce merchants impacted by third-party app data breach SC Media · Sep 22 general VA criticizes Baylor Genetics for delayed notification after data breach SC Media · Sep 22