Proofpoint attributes a browser implant exploiting CVE-2026-42897 to TA488. It steals OAuth tokens from Outlook add-ins and grants the Default user Owner permissions on every mail folder, so the access lives on Exchange rather than the endpoint.