logo

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

ID: ab57b86c-9bb6-5f33-8646-80ce69d084db

STIX ID: report--ab57b86c-9bb6-5f33-8646-80ce69d084db

Feed Name: Ars Technica Security (category)

Threat Score
90/100

Date Published: 2026-07-30

Date Updated: 2026-07-31

Author: Dan Goodin

...
...

Proofpoint and NSA reporting indicates Russian state-linked group TA488 (Laundry Bear/Void Blizzard) exploited a maximum-severity Exchange OWA XSS (CVE-2026-42897) — possibly as a zero-day — to deliver a previously unseen browser-based JavaScript backdoor named OWAReaper via a 'half-click' email exploit, enabling persistent access and credential theft; Microsoft issued mitigations in May and patched the flaw in July.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.