Bottom line: Russian threat actors are exploiting an OWA vulnerability to maintain mailbox access after credential rotation, targeting critical infrastructure and government entities in the USA and Europe.
Russian threat actors, who have previously exploited the Zimbra vulnerability, have been attacking U.S. and European government agencies and companies in telecommunications, finance, hospitality, and aerospace since July 22, 2026, via a security flaw in Microsoft Outlook Web Access (OWA).
The observed campaign began on July 22, 2026 and targets government and private sector entities. The targeted sectors include government agencies in the USA and Europe, telecommunications providers, financial institutions, hospitality companies, and aerospace and defense companies.
The attackers are exploiting a security vulnerability in Microsoft OWA that allows them to maintain access to compromised mailboxes even after credential rotation. This significantly complicates incident response, as standard password reset procedures are insufficient to remove the attacker from the system.
The same threat actor group was previously involved in exploiting a patched Zimbra vulnerability. The targeting of government agencies, critical infrastructure, and the financial sector indicates a strategic intelligence collection objective. For CISOs, OWA systems are a prioritized audit and patch target, and mailbox access should be monitored for suspicious activity.
Source: thehackernews.com · Published July 30, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.