Outlook OWA and Russia Linked Cyber Attacks and Mitigations
Russia-linked threat group called Laundry Bear (also tracked as Void Blizzard/TA488) exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access (OWA) to maintain long-term access to email accounts. Key points reported The vulnerability is identified as CVE-2026-42897 , described as an XSS (cross-site scripting) flaw in Exchange OWA. The attack reportedly requires a victim to open or view a malicious email in OWA, without clicking links or attachments. Researchers have referred to this as a "half-click" exploit. The malware, called OWAReaper , is said to run inside the OWA reading pane and remove traces of the exploit from the email after execution. Reported persistence mechanisms include: Granting Owner-level mailbox permissions to a low-privilege account. Injecting malicious content into cached emails using browser-side storage mechanisms. The campaign has been linked by Proofpoint to t...