🟠 High  |  Source: The Hacker News


Russian threat actors are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to mailboxes even after victims rotate their credentials — a technique that effectively defeats a common incident response measure. The campaign, active since 22 July 2026, targets US and European government bodies alongside telecoms, finance, hospitality, and aerospace organisations. This follows the same group’s recent exploitation of a similar flaw in Zimbra, indicating a deliberate focus on webmail persistence techniques.

Security Architect’s Take: Audit all Exchange Online and OWA-connected application tokens, OAuth grants, and delegated permissions immediately, as credential rotation alone will not evict an attacker exploiting this class of vulnerability. Ensure conditional access policies enforce device compliance and revoke all active sessions as part of any incident response runbook, and prioritise applying the relevant Microsoft patch across hybrid Exchange environments.

Original advisory: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation