Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Hackers Leverage Microsoft OWA Vulnerability

Russian Hackers Leverage Microsoft OWA Vulnerability

Posted on July 30, 2026 By CWS

Russian threat actors have been identified exploiting a flaw in Microsoft Outlook Web Access (OWA) to target various sectors in the U.S. and Europe. This development follows their previous use of a Zimbra vulnerability. The attackers focus on government, telecommunications, financial, hospitality, and aerospace entities.

Exploiting CVE-2026-42897

The cyber campaign, which began on July 22, 2026, leverages CVE-2026-42897, a cross-site scripting vulnerability in OWA with a CVSS score of 8.1. Microsoft had identified this flaw as being exploited since May 2026. Proofpoint attributes the attacks to a group called Laundry Bear, also known as TA488, which previously exploited a Zimbra vulnerability.

In these attacks, adversaries sent emails from compromised accounts, leading to the execution of a JavaScript payload, ZimReaper, that extracted data from the victim’s email. The group has improved its tactics, employing more sophisticated loading methods and malware tools.

Techniques and Tactics

The attackers use compromised accounts to send phishing emails without requiring recipient interaction. These emails mimic legitimate communications, avoiding any URLs or attachments to reduce suspicion. Once opened, they trigger the execution of malicious code exploiting CVE-2026-42897.

The malicious JavaScript uses an onload event handler to activate upon opening. It assembles and executes a script embedded in the message, leading to the deployment of a browser-based implant, OWAReaper, which maintains persistent access to the compromised accounts.

Persistent Threats and Responses

OWAReaper is an evolved form of ZimReaper, designed to operate within the OWA reading pane. It manipulates Outlook APIs to rewrite emails on the Exchange server, removes exploit traces, and uses sophisticated methods to maintain access, even after credential changes or system re-imaging.

The malware also utilizes GitHub and attacker-sent emails as command-and-control channels. It checks for messages with specific structures to execute commands discreetly, often using encrypted paths for data exfiltration.

Proofpoint’s findings suggest that the infrastructure for these attacks was set up months before the vulnerability was publicly disclosed, indicating possible zero-day exploitation. The group’s activity paused from February to July 2026, but the new wave highlights their continued focus on intelligence gathering across various sectors.

The persistent nature of these attacks underscores the need for organizations to enhance their security measures and remain vigilant against evolving cyber threats.

The Hacker News Tags:Aerospace, CVE-2026-42897, cyber attack, Cybersecurity, financial sector, government sectors, Microsoft, OWA vulnerability, OWAReaper, Proofpoint, Russian hackers, TA488, Telecommunications, ZimReaper

Post navigation

Previous Post: TA488 Exploits Outlook Web Access Flaw Before Patch
Next Post: US and Allies Revise Software Bill of Materials Guidelines

Related Posts

Researchers Disclose Google Gemini AI Flaws Allowing Prompt Injection and Cloud Exploits Researchers Disclose Google Gemini AI Flaws Allowing Prompt Injection and Cloud Exploits The Hacker News
FIFA World Cup 2026: Rising Scam Threats Alert FIFA World Cup 2026: Rising Scam Threats Alert The Hacker News
How To Browse Faster and Get More Done Using Adapt Browser How To Browse Faster and Get More Done Using Adapt Browser The Hacker News
Critical Vulnerability in Cursor Allows Windows Code Execution Critical Vulnerability in Cursor Allows Windows Code Execution The Hacker News
What Should We Learn From How Attackers Leveraged AI in 2025? What Should We Learn From How Attackers Leveraged AI in 2025? The Hacker News
TrojPix Exploits Pixel Modulation to Leak Data TrojPix Exploits Pixel Modulation to Leak Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Industry Urged to Prioritize Safety to Prevent Potential Risks
  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed
  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Industry Urged to Prioritize Safety to Prevent Potential Risks
  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed
  • CISA Highlights Critical Security Flaws in Artifactory and RouterOS

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark