Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
Reported exploitedOutlook Web Access (OWA)TA488Our summary
A Russian-affiliated hacking group, Laundry Bear (also known as Void Blizzard or TA488), is actively exploiting a cross-site scripting vulnerability in Microsoft Exchange (CVE-2026-42897) to deploy a sophisticated backdoor called OWAReaper. The exploit targets government and private sector organizations in the U.S. and Europe through seemingly innocuous emails that trigger malicious code when opened. Once activated, the malware steals credentials, grants unauthorized access to mailboxes, and persists across device reimages. Microsoft issued a patch for this flaw in June 2026, but attackers had already been using it as a zero-day since March. Organizations are urged to apply the fix immediately and scan for signs of compromise.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.