Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Hackers Leverage Microsoft OWA Vulnerability

Russian Hackers Leverage Microsoft OWA Vulnerability

Posted on July 30, 2026 By CWS

Russian threat actors have been identified exploiting a flaw in Microsoft Outlook Web Access (OWA) to target various sectors in the U.S. and Europe. This development follows their previous use of a Zimbra vulnerability. The attackers focus on government, telecommunications, financial, hospitality, and aerospace entities.

Exploiting CVE-2026-42897

The cyber campaign, which began on July 22, 2026, leverages CVE-2026-42897, a cross-site scripting vulnerability in OWA with a CVSS score of 8.1. Microsoft had identified this flaw as being exploited since May 2026. Proofpoint attributes the attacks to a group called Laundry Bear, also known as TA488, which previously exploited a Zimbra vulnerability.

In these attacks, adversaries sent emails from compromised accounts, leading to the execution of a JavaScript payload, ZimReaper, that extracted data from the victim’s email. The group has improved its tactics, employing more sophisticated loading methods and malware tools.

Techniques and Tactics

The attackers use compromised accounts to send phishing emails without requiring recipient interaction. These emails mimic legitimate communications, avoiding any URLs or attachments to reduce suspicion. Once opened, they trigger the execution of malicious code exploiting CVE-2026-42897.

The malicious JavaScript uses an onload event handler to activate upon opening. It assembles and executes a script embedded in the message, leading to the deployment of a browser-based implant, OWAReaper, which maintains persistent access to the compromised accounts.

Persistent Threats and Responses

OWAReaper is an evolved form of ZimReaper, designed to operate within the OWA reading pane. It manipulates Outlook APIs to rewrite emails on the Exchange server, removes exploit traces, and uses sophisticated methods to maintain access, even after credential changes or system re-imaging.

The malware also utilizes GitHub and attacker-sent emails as command-and-control channels. It checks for messages with specific structures to execute commands discreetly, often using encrypted paths for data exfiltration.

Proofpoint’s findings suggest that the infrastructure for these attacks was set up months before the vulnerability was publicly disclosed, indicating possible zero-day exploitation. The group’s activity paused from February to July 2026, but the new wave highlights their continued focus on intelligence gathering across various sectors.

The persistent nature of these attacks underscores the need for organizations to enhance their security measures and remain vigilant against evolving cyber threats.

The Hacker News Tags:Aerospace, CVE-2026-42897, cyber attack, Cybersecurity, financial sector, government sectors, Microsoft, OWA vulnerability, OWAReaper, Proofpoint, Russian hackers, TA488, Telecommunications, ZimReaper

Post navigation

Previous Post: TA488 Exploits Outlook Web Access Flaw Before Patch
Next Post: US and Allies Revise Software Bill of Materials Guidelines

Related Posts

Banking Malware Targets Windows and Android Devices Banking Malware Targets Windows and Android Devices The Hacker News
How the Browser Became the Main Cyber Battleground How the Browser Became the Main Cyber Battleground The Hacker News
CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers The Hacker News
A Browser Extension Risk Guide After the ShadyPanda Campaign A Browser Extension Risk Guide After the ShadyPanda Campaign The Hacker News
Security Risks in Popular VS Code Extensions Identified Security Risks in Popular VS Code Extensions Identified The Hacker News
Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AtlasRAT Malware Hidden in Fake Flash Installer
  • Data Center Vulnerabilities Expose Critical Systems to Threats
  • State-Sponsored Campaign Exploits Korean Sites for Cyber Attacks
  • Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet
  • Critical Flaw in Ruflo AI Exposes Systems to Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AtlasRAT Malware Hidden in Fake Flash Installer
  • Data Center Vulnerabilities Expose Critical Systems to Threats
  • State-Sponsored Campaign Exploits Korean Sites for Cyber Attacks
  • Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet
  • Critical Flaw in Ruflo AI Exposes Systems to Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark