Max-severity Exchange server flaw under active exploitation by Kremlin hackers
ID: ab57b86c-9bb6-5f33-8646-80ce69d084db
STIX ID: report--ab57b86c-9bb6-5f33-8646-80ce69d084db
Feed Name: Ars Technica Security (category)
Threat Score
Proofpoint and NSA reporting indicates Russian state-linked group TA488 (Laundry Bear/Void Blizzard) exploited a maximum-severity Exchange OWA XSS (CVE-2026-42897) — possibly as a zero-day — to deliver a previously unseen browser-based JavaScript backdoor named OWAReaper via a 'half-click' email exploit, enabling persistent access and credential theft; Microsoft issued mitigations in May and patched the flaw in July.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
