View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

TA488 Exploited Outlook Web Access 0-Day XSS Flaw to Compromise

๐Ÿšจ ACTIVE EXPLOITATION

  • TA488 Exploited Outlook Web Access 0-Day XSS Flaw to Compromise Mailboxes CVE-2026-42897
    TA488 exploited a zero-day Outlook Web Access XSS flaw to run malicious code in victim browsers.
    • Targets: Government, telecom, finance, hospitality, aerospace sectors in US and Europe
    • Vulnerability: CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access on-premises Exchange
    • Attack: Malicious emails without attachments or links trigger JavaScript payload when opened in webmail
    • Payload: OWAReaper implant runs in browser, steals mailbox data, alters folder permissions for persistence
    • Command & Control: Uses GitHub commits, email commands, HTTPS image traffic, and DNS tunneling for data exfiltration
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ’ฅ BREACHES & INCIDENTS

  • UK Department for Education hacked, 607K records of officials leaked in 2026 breach
    The UK Department for Education suffered a data breach exposing 607,000 records.
    • Applies to UK Department for Education staff and officials, including head teachers and senior leaders
    • Exposed data includes names, job titles, email addresses, and phone numbers
    • Attack exploited the DfE help desk and Turing Scheme portals via social engineering
    • Incident occurred July 26, 2026, disclosed July 29, 2026, linked to hacker group ExfilSquad
    • Part of wider UK government cyberattacks; data risks targeted phishing and impersonation
      ๐Ÿ“Ž Coverage: paperweight.email ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • OS Command Injection Vulnerability Found in OCPP Agent Before Version 1.9.1 CVE-2026-44098
    An unauthenticated remote attacker can perform OS command injection in OCPP Agent.

    • Applies to OCPP Agent versions before 1.9.1
    • Vulnerability allows OS command injection via the charge_box_id parameter
    • Attack requires remote access to OCPP backend with firewall bypass
    • Execution occurs as limited user charx-oa, potentially disrupting charging operations
    • CVE ID: CVE-2026-44098, CVSS 8.6/8.8, CWE-78 OS Command Injection
      ๐Ÿ“Ž Coverage: cve.threatint.com ยท ๐Ÿ“„ Original: cve.threatint.com ยท ๐Ÿ‘ via CVE ThreatInt
  • Fake N26 Support Calls Deploy Copybara Android RAT to Control Banking Apps
    Attackers use fake N26 support calls to install Copybara RAT on Android devices.

    • Targets Android users of N26 banking app via voice phishing calls impersonating support
    • Victims are tricked into visiting fake login pages and installing malicious APKs outside app stores
    • Malware Copybara abuses Android Accessibility permissions to remotely control banking apps
    • Copybara can capture screens, record audio/video, log keys, and intercept messages and calls
    • Attackers communicate via MQTT channels hosted on hard-coded command-and-control servers
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News
  • Claude Opus 5 AI Agent Accidentally Wipes Entire Production Database in Minutes
    Claude Opus 5 AI agent accidentally wiped a production database during a personal project.

    • Applies to developers using Anthropic's Claude Opus 5 AI in Ultracode mode
    • Vulnerability: AI executed a Prisma migration command targeting a live Supabase production database
    • Attack vector: AI connected directly with broad access to production DB and ran schema-altering commands autonomously
    • Impact: All 22 tables wiped, including key datasets like tools, users, reviews, and comparison entries
    • Cause: Misconfigured --shadow-database-url pointed to production, triggering full schema reset from outdated migrations
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ“‹ ADVISORIES

  • Google Chrome 151 Fixes 370 Vulnerabilities Including 80 Critical and High-Severity Bugs
    Google released Chrome 151 to patch 370 vulnerabilities including critical use-after-free bugs.

    • Applies to Google Chrome versions 151.0.7922.71/.72 on Windows, macOS, and Linux
    • Fixes 370 vulnerabilities including 7 critical bugs and 71 high-severity defects
    • Critical bugs include use-after-free issues in Compositing, Views, Skia, Ozone, and validation flaws in Dawn and ANGLE
    • Over 30 vulnerabilities affect ANGLE, Chrome's WebGL graphics backend
    • Google discovered 349 issues and credited external researchers for 21, paying $58,500 in bounties
      ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • Node.js July 2026 Update Fixes 11 Vulnerabilities Including HTTP/2 and Permission Bypass
    Node.js released security updates fixing 11 vulnerabilities across active branches.

    • Applies to Node.js versions 22.x, 24.x, and 26.x (v22.23.2, v24.18.1, v26.5.1)
    • Fixes 11 vulnerabilities including HTTP/2 memory limit bypass and heap use-after-free
    • Addresses permission model flaw allowing filesystem access outside allowlist
    • Patches HTTPS mTLS identity reuse and hostname verification bypass issues
    • Resolves crashes from oversized DNS responses, SQLite, Zlib, and HTTP request smuggling
      ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News

๐Ÿ”“ CVEs & KEV

  • Other: 19 CVEs (worst 9.8)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check