← Back to Feed
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
CVE-2026-42897CVE-2025-66376
July 30, 2026 · The Hacker News · Severity: HIGH
Russian threat actors tracked as Laundry Bear (Void Blizzard, TA488) exploited CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Outlook Web Access (OWA), to maintain mailbox access even after credential rotation. The campaign, active since July 22, 2026, targets U.S. and European government entities and the telecommunications, financial, hospitality, and aerospace sectors. The same group was previously linked to zero-day exploitation of CVE-2025-66376 in Zimbra. By combining the OWA XSS with Zimbra exploitation and credential harvesting via adversary-in-the-middle (AiTM) proxy infrastructure, the attackers achieve persistent mailbox access that outlives password changes.
Key Takeaways
- Russian threat actors exploited CVE-2026-42897 (XSS in Microsoft OWA, CVSS 8.1) to maintain mailbox access even after credentials were rotated, targeting government and critical infrastructure sectors.
- The campaign uses a multi-stage approach: Zimbra XSS exploitation, credential harvesting via AiTM proxies, then OWA XSS abuse for persistent access, all attributed to Laundry Bear (Void Blizzard).
- Credential rotation alone is insufficient protection against these attacks, as the XSS-based session persistence survives password changes.