// Microsoft 365CRITICAL
Russian state-sponsored group Laundry Bear (tracked as TA488/Void Blizzard) deployed OWAReaper, a sophisticated malware implant targeting Microsoft Exchange servers via CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access. The campaign, active since July 22, 2026, targeted US and European government agencies and critical-sector organizations. OWAReaper establishes persistent Exchange folder permissions that survive credential rotation and device re-imaging; primary command-and-control uses GitHub commit messages to evade detection.
- Russian Hackers Breached Exchange Servers With OWAReaper: Implan(opens in a new tab)
- TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Mi(opens in a new tab)
- Laundry Bear's new Microsoft Exchange attack triggers on email o(opens in a new tab)
- Laundry Bear's new Microsoft Exchange attack triggers on email o(opens in a new tab)
- Russian hackers deploy OWAReaper Exchange backdoor(opens in a new tab)
- Week in review: Claude breached three companies during tests, AD(opens in a new tab)
// Get alerts for Microsoft 365