Russian threat actors have been exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain access to compromised mailboxes even after credential rotation, targeting government entities and multiple industries in the US and Europe since July 22, 2026. This exploitation allows attackers to bypass security measures designed to limit access after a password reset. The vulnerability, which has been patched, was used in conjunction with other tactics to gain persistent access to sensitive information. The same threat actors were previously linked to the exploitation of a now-patched Zimbra vulnerability1. This incident highlights the importance of implementing robust security measures beyond just credential rotation to prevent prolonged access by malicious actors. The ability of these actors to quickly adapt and exploit new vulnerabilities poses a significant threat to organizations, making it crucial for practitioners to stay vigilant and prioritize comprehensive security protocols.