Security · 2h ago
Russian Hackers Exploit Microsoft OWA Flaw to Retain Email Access
Russian threat actors are exploiting a Microsoft Outlook Web Access vulnerability to target U.S. and European government, telecom, finance, hospitality, and aerospace entities. The campaign began July 22, 2026, and allows attackers to maintain mailbox access even after credential rotation. The flaw is separate from a previously patched Zimbra vulnerability linked to the same group.
Meridian48 take
The attack's ability to persist after credential changes suggests a deeper compromise than a simple password theft, raising questions about Microsoft's detection and response.
Read the full reporting
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation →
The Hacker News
microsoft-owarussian-hackers