Russian hackers exploit Exchange zero-day for persistent email access

Laundry Bear (also known as Void Blizzard), a Russian state-sponsored hacking group, is exploiting an Outlook Web Access zero-day vulnerability in Microsoft Exchange to deliver the OWAReaper backdoor. The campaign targets organizations in Europe and the US for long-term mailbox persistence.

8 reports · 6 independenttech · other

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Russian hackers exploited Exchange OWA zero-day to access mailboxes

kite:cybersecurityother61d ago kagi ↗

The Russia-aligned hacking group TA488, also known as Laundry Bear or Void Blizzard, exploited a now-patched Microsoft Exchange Outlook Web Access flaw tracked as CVE-2026-42897 to access mailboxes through crafted webmail messages [bleepingcomputer.com#1][cybersecuritynews.com#1]. Proofpoint identified the campaign and named the browser-based implant OWAReaper, which attackers used against governm

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access https://www. bleepingcomputer.com/news/secu rity/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/?

mastodon:infosec-exchangeother61d ago wire ×2 kagi ↗

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access https://www. bleepingcomputer.com/news/secu rity/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D

🤖 Laundry Bear (Void Blizzard), Russian state-sponsored group, exploits Exchange OWA zero-day to deliver OWAReaper backdoor. Targets orgs in Europe and US for long-term mailbox persistence. CISA noti

mastodon:infosec-exchangeother61d ago kagi ↗

🤖 Laundry Bear (Void Blizzard), Russian state-sponsored group, exploits Exchange OWA zero-day to deliver OWAReaper backdoor. Targets orgs in Europe and US for long-term mailbox persistence. CISA notified. 🔗 https://www. bleepingcomputer.com/news/secu rity/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/ # 0day # RCE # CyberSec # Exchange # APT

🤖 Russian APT Laundry Bear exploits an Exchange OWA 0-day to deploy the OWAReaper backdoor. Targets US/EU govt, telecom, finance, aerospace. Provides persistent mailbox access even after credential r

mastodon:infosec-exchangeother61d ago kagi ↗

🤖 Russian APT Laundry Bear exploits an Exchange OWA 0-day to deploy the OWAReaper backdoor. Targets US/EU govt, telecom, finance, aerospace. Provides persistent mailbox access even after credential rotation. 🔗 https://www. bleepingcomputer.com/news/secu rity/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/ # Exploit # CyberSec # APT # ZeroDay