< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-30T13:10:48+05:30

Russian Threat Actors Exploit Microsoft OWA XSS Vulnerability for Persistent Mailbox Access

Russian threat actors are exploiting a Microsoft OWA cross-site scripting vulnerability (CVE-2026-42897) to deploy OWAReaper, a sophisticated JavaScript implant that maintains persistent mailbox access even after credential rotation. The malware uses advanced techniques like browser-based persistence and GitHub-based command-and-control to evade detection and retain access.

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.

The activity, which began on July 22, 2026, involves the

Read original article

*** END OF TRANSMISSION ***