Russian Hackers Exploit OWA Zero-Day to Hijack Mailboxes Just by Opening an Email
Security researchers at Proofpoint disclosed on July 29, 2026, that a threat actor tracked as TA488 — also known as Void Blizzard or Laundry Bear — is actively exploiting a critical zero-day vulnerability, CVE-2026-42897, in Microsoft Exchange Outlook Web Access. The attack, dubbed OWAReaper, is triggered simply by opening a specially crafted email in OWA's reading pane, which silently executes hidden JavaScript reconstructed from image fragments without dropping any files on the victim's device. Once executed, the implant steals browser-saved credentials and OAuth tokens, grants the attacker Owner-level permissions on all mail folders, and embeds itself into OWA settings and the offline mail cache to survive password changes and device reimaging. The malicious code erases itself from the email body after execution, making the message appear benign during post-incident reviews, and leaves no traces detectable by standard endpoint detection tools. Organizations are urged to apply the CVE-2026-42897 patch immediately, audit Exchange folder permissions and OWA settings, and monitor for anomalous GitHub API traffic originating from OWA browser sessions.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in