Russian threat actors have been exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain access to compromised mailboxes even after credential rotation, targeting government entities and multiple industries in the US and Europe since July 22, 2026. This exploitation allows attackers to bypass security measures designed to limit access after a password reset. The vulnerability, which has been patched, was used in conjunction with other tactics to gain persistent access to sensitive information. The same threat actors were previously linked to the exploitation of a now-patched Zimbra vulnerability1. This incident highlights the importance of implementing robust security measures beyond just credential rotation to prevent prolonged access by malicious actors. The ability of these actors to quickly adapt and exploit new vulnerabilities poses a significant threat to organizations, making it crucial for practitioners to stay vigilant and prioritize comprehensive security protocols.
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
⚠️ Critical Alert
Why This Matters
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft.
References
- The Hacker News. (2026, July 30). Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation. *The Hacker News*. https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html
Original Source
The Hacker News
Read original →