Signal

Russian hackers exploit Microsoft Exchange and OWA vulnerabilities for mailbox takeover

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-07-30 07:40 UTCUpdated 2026-07-30 12:00 UTC
rss
cveexploitsthreat_actorsincident_responsesecurity_policy
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Overview

Since July 22, 2026, the Russia-aligned threat group TA488 (also known as Void Blizzard and Laundry Bear) has exploited a Microsoft Exchange cross-site scripting vulnerability (CVE-2026-42897) in Outlook Web Access (OWA) to gain mailbox access without requiring users to click links or open attachments.

Entities
Microsoft
Score total
1.14
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • The attacks began recently on July 22, 2026, indicating an active and ongoing threat campaign.
  • Microsoft has issued emergency updates, but many systems remain vulnerable.
  • Awareness of these tactics is critical for defenders to mitigate mailbox compromise and credential theft.
Why it matters
  • The exploited Exchange vulnerability allows mailbox takeover without user clicks, increasing risk of stealthy breaches.
  • Targets include sensitive government and critical industry sectors, raising national security concerns.
  • Phishing attacks leveraging legitimate Microsoft login pages show attackers' evolving sophistication.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • TA488 exploited CVE-2026-42897 in Microsoft Exchange OWA to gain mailbox access without user clicks
  • Phishing campaigns abused legitimate Microsoft login pages to trick users
How sources frame it
  • CSO Online: neutral
  • The Hacker News: neutral
  • Infosecurity Magazine: neutral
All evidence
All evidence
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Infosecurity Magazine · infosecurity-magazine.com · 2026-07-30 12:00 UTC
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
CSO Online · csoonline.com · 2026-07-30 10:45 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
  • Infosecurity Magazine (1)
  • CSO Online (1)
  • thehackernews (1)
Top origin domains (this list)
  • infosecurity-magazine.com (1)
  • csoonline.com (1)
  • thehackernews.com (1)