A password reset no longer clears this kind of mailbox compromise. TA488 has shifted its half-click playbook from Zimbra to Microsoft OWA, so the real foothold sits in the webmail layer and survives credential rotation and device re-imaging.
Proofpoint says the group began using CVE-2026-42897 in OWA on July 22 and deployed OWAReaper against government, telecommunications, financial, hospitality, and aerospace targets. Microsoft says the XSS flaw had already been exploited as far back as May 2026, and the same browser-session attack model lets a message become persistent mailbox access instead of a one-time login theft.
The move from a niche mail stack to mainstream OWA widens the target pool and makes standard cleanup look complete when it is not.