Russian actors abuse patched Microsoft OWA flaw to retain mailbox access
Source headline: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Intelligence Summary
Russian-aligned threat actors are exploiting a Microsoft Outlook Web Access (OWA) vulnerability that has since been patched. The campaign targets organizations across the U.S. and Europe, including government and several regulated industries. The attackers use the flaw to preserve mailbox access even after victim credentials are rotated. This indicates a persistence mechanism rather than a one-time compromise. Organizations running OWA should ensure the latest security updates are fully applied and validate mailbox access controls. Incident responders should review OWA logs for suspicious sessions and post-rotation access attempts.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.