← Back

Wire · technology

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Published

30 July 2026

Topic

technology

Sectors

Cybersecurity

Source

Read at thehackernews.com

Verified

Fusion42 · 30 July 2026 · Fusion42 review

A Russian hacking group is using a 'half-click' exploit against a vulnerability (CVE-2026-42897) in Microsoft's Outlook Web Access. The attack installs a new implant, OWAReaper, which gives them persistent access to mailboxes even after passwords are changed, targeting government and corporate entities in the US and Europe.

This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.

◆ The Wire takeaway

Your standard incident response playbook is now obsolete for this threat. Simply rotating credentials won't evict these attackers; you need to assume breach and actively hunt for their persistence mechanism in your Outlook servers.

Related on Wire

Topics

Cybersecuritycybersecurityowamicrosoft-exchangerussiaxss-exploitpersistent-access