TA488 exploits OWA cross-site scripting flaw to plant browser implants that survive credential rotation.