CyberSecurity News
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
AI summary
Russian hackers have been exploiting a vulnerability in Microsoft Outlook Web Access to maintain access to mailboxes even after credentials have been rotated. The targets of this activity include government entities in the US and Europe, as well as companies in the telecommunications, financial, hospitality, and aerospace sectors. This exploitation began on July 22, 2026, and is linked to the same threat actors who recently exploited a vulnerability in Zimbra. The vulnerability in Microsoft OWA is now patched. The hackers' goal is to retain access to targeted mailboxes despite credential changes.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

