FILTERING BY: CLEAR FILTER

Microsoft Outlook Web Access OWA Exploitation by Laundry Bear

Russian-aligned APT Laundry Bear (TA488) is exploiting CVE-2026-42897, a high-severity Cross-Site Scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA), to achieve persistent mailbox access. The attack utilizes a "half-click" vector, where merely viewing a malicious email in the OWA reading pane triggers the execution of the "OWAReaper" JavaScript implant. The adversary achieves server-side persistence by abusing Outlook add-ins with ReadWriteMailbox permissions to harvest OAuth tokens. This mechanism allows attackers to maintain access even after password resets or endpoint re-imaging. Affected environments include on-premises Exchange Server 2016, 2019, and Subscription Edition, while Exchange Online remains unaffected.


LINK COPIED TO CLIPBOARD