// Alert

Microsoft 365 threat report

Russian state-sponsored group Laundry Bear (tracked as TA488/Void Blizzard) deployed OWAReaper, a sophisticated malware implant targeting Microsoft Exchange servers via CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access. The campaign, active since July 22, 2026, targeted US and European government agencies and critical-sector organizations. OWAReaper establishes persistent Exchange folder permissions that survive credential rotation and device re-imaging; primary command-and-control uses GitHub commit messages to evade detection.

// Get alerts for Microsoft 365