Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Hackers Leverage Microsoft OWA Vulnerability

Russian Hackers Leverage Microsoft OWA Vulnerability

Posted on July 30, 2026 By CWS

Russian threat actors have been identified exploiting a flaw in Microsoft Outlook Web Access (OWA) to target various sectors in the U.S. and Europe. This development follows their previous use of a Zimbra vulnerability. The attackers focus on government, telecommunications, financial, hospitality, and aerospace entities.

Exploiting CVE-2026-42897

The cyber campaign, which began on July 22, 2026, leverages CVE-2026-42897, a cross-site scripting vulnerability in OWA with a CVSS score of 8.1. Microsoft had identified this flaw as being exploited since May 2026. Proofpoint attributes the attacks to a group called Laundry Bear, also known as TA488, which previously exploited a Zimbra vulnerability.

In these attacks, adversaries sent emails from compromised accounts, leading to the execution of a JavaScript payload, ZimReaper, that extracted data from the victim’s email. The group has improved its tactics, employing more sophisticated loading methods and malware tools.

Techniques and Tactics

The attackers use compromised accounts to send phishing emails without requiring recipient interaction. These emails mimic legitimate communications, avoiding any URLs or attachments to reduce suspicion. Once opened, they trigger the execution of malicious code exploiting CVE-2026-42897.

The malicious JavaScript uses an onload event handler to activate upon opening. It assembles and executes a script embedded in the message, leading to the deployment of a browser-based implant, OWAReaper, which maintains persistent access to the compromised accounts.

Persistent Threats and Responses

OWAReaper is an evolved form of ZimReaper, designed to operate within the OWA reading pane. It manipulates Outlook APIs to rewrite emails on the Exchange server, removes exploit traces, and uses sophisticated methods to maintain access, even after credential changes or system re-imaging.

The malware also utilizes GitHub and attacker-sent emails as command-and-control channels. It checks for messages with specific structures to execute commands discreetly, often using encrypted paths for data exfiltration.

Proofpoint’s findings suggest that the infrastructure for these attacks was set up months before the vulnerability was publicly disclosed, indicating possible zero-day exploitation. The group’s activity paused from February to July 2026, but the new wave highlights their continued focus on intelligence gathering across various sectors.

The persistent nature of these attacks underscores the need for organizations to enhance their security measures and remain vigilant against evolving cyber threats.

The Hacker News Tags:Aerospace, CVE-2026-42897, cyber attack, Cybersecurity, financial sector, government sectors, Microsoft, OWA vulnerability, OWAReaper, Proofpoint, Russian hackers, TA488, Telecommunications, ZimReaper

Post navigation

Previous Post: TA488 Exploits Outlook Web Access Flaw Before Patch
Next Post: US and Allies Revise Software Bill of Materials Guidelines

Related Posts

Winning Against AI-Based Attacks Requires a Combined Defensive Approach Winning Against AI-Based Attacks Requires a Combined Defensive Approach The Hacker News
New Windows Vulnerability PoC Released Post Patch Update New Windows Vulnerability PoC Released Post Patch Update The Hacker News
Ubuntu Security Flaw CVE-2026-3888 Enables Root Access Ubuntu Security Flaw CVE-2026-3888 Enables Root Access The Hacker News
WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks WhatsApp Malware ‘Maverick’ Hijacks Browser Sessions to Target Brazil’s Biggest Banks The Hacker News
Guide to Managing AI Usage in Enterprises Guide to Managing AI Usage in Enterprises The Hacker News
Russian Hacker Jailed for Botnet Ransomware Crimes Russian Hacker Jailed for Botnet Ransomware Crimes The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet
  • Critical Flaw in Ruflo AI Exposes Systems to Attack
  • FCC Restricts Foreign Robots and Inverters Over Cyber Threats
  • Cisco Urges Update Amid Firewall Vulnerability Exploit
  • US and Allies Revise Software Bill of Materials Guidelines

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet
  • Critical Flaw in Ruflo AI Exposes Systems to Attack
  • FCC Restricts Foreign Robots and Inverters Over Cyber Threats
  • Cisco Urges Update Amid Firewall Vulnerability Exploit
  • US and Allies Revise Software Bill of Materials Guidelines

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark