Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Chronological Source Flow
Back

AI Fusion Summary

Russia-aligned threat group TA488, also known as Void Blizzard and Laundry Bear, exploited a cross-site scripting vulnerability CVE-2026-42897 in Microsoft Exchange’s Outlook Web Access. Starting July 22, the group used specially crafted emails to install browser-based backdoors, enabling mailbox takeovers. These attacks targeted government organizations in the US and Europe, alongside the aerospace, financial, hospitality, and telecommunications sectors. Proofpoint reported that this half-click exploit allows attackers to maintain access even after credential rotation occurs.
Community Comments
Loading updates...
0