TA488 exploits OWA cross-site scripting flaw to plant browser implants that survive credential rotation.
Organizations using on premises Exchange Server are urged to patch an XSS flaw in Outlook Web Access that CISA confirms…