ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Cybersecurity

Russian actors abuse patched Microsoft OWA flaw to retain mailbox access

Source headline: Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

Russian-aligned threat actors are exploiting a Microsoft Outlook Web Access (OWA) vulnerability that has since been patched. The campaign targets organizations across the U.S. and Europe, including government and several regulated industries. The attackers use the flaw to preserve mailbox access even after victim credentials are rotated. This indicates a persistence mechanism rather than a one-time compromise. Organizations running OWA should ensure the latest security updates are fully applied and validate mailbox access controls. Incident responders should review OWA logs for suspicious sessions and post-rotation access attempts.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#credential-rotation #government-targeting #patched-vulnerability #mailbox-persistence #owa #russian-threat-actors
Original reporting The Hacker News Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Open original source