#1
BleepingComputer
general
July 29, 2026 at 23:44 UTC
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
By Ionut Ilascu
AI Summary
Russian state-sponsored group Laundry Bear (aka Void Blizzard) is actively exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access (OWA) to deploy a backdoor called OWAReaper, enabling persistent long-term mailbox access. This is a significant escalation from the group's previously documented credential-theft campaigns and represents a critical threat to organizations running Exchange with OWA exposed. Security teams should prioritize patching Exchange and auditing OWA-facing infrastructure immediately.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →