Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Reported exploitedMicrosoft Exchange Outlook Web Access (OWA)Laundry BearOur summary
A Russian state-backed hacking group, known as Laundry Bear or Void Blizzard, is exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access (OWA) to gain long-term access to email accounts. The flaw, tracked as CVE-2026-42897, allows attackers to execute arbitrary JavaScript when users open specially crafted emails. This leads to the deployment of a sophisticated backdoor named OWAReaper, which enables persistent access and data theft. Security firm Proofpoint has observed this activity targeting multiple sectors, including government agencies and critical infrastructure. The exploit bypasses traditional detection methods by leveraging improper HTML sanitization and maintaining access even after system reinstallation.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.