HeadlinesBriefing favicon HeadlinesBriefing.com

Kremlin Hackers Exploit Exchange Server Flaw

Ars Technica •
×

Russian state-sponsored hackers, identified as TA488 (also known as Laundry Bear and Void Blizzard), are actively exploiting a maximum-severity vulnerability in Microsoft Exchange Server. This flaw, tracked as CVE-2026-42897, allows attackers to backdoor unpatched systems and steal sensitive information, including credentials.

Researchers from Proofpoint noted that TA488 is leveraging this cross-site-scripting (XSS) vulnerability, which requires only an email to be opened in Outlook Web Access (OWA) to trigger compromise. This "half-click" exploit enables the execution of malicious JavaScript, leading to the installation of a sophisticated, custom-built browser extension named OWAReaper. Proofpoint described OWAReaper as the most advanced backdoor they have observed delivered via such an exploit.

Microsoft released mitigation advice for the vulnerability in May and a patch in July, assigning it a maximum severity rating. Proofpoint suggests TA488 may have exploited this flaw as a zero-day. The group's increased use of improved "half-click" exploits indicates a significant advancement in their tradecraft and capabilities, with the goal of gaining persistent access to victims' OWA accounts.