[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access-ms8ns4vx":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"5fcc1fdd-6467-4f7e-b738-3eab4d4d313f","Russian hackers exploit Exchange OWA zero-day for long-term mailbox access","russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access-ms8ns4vx","Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox access and enables credential harvesting.","critical","advisory",[12],"CVE-2026-42897",[14,15,16],"Exchange Outlook Web Access","Zimbra email servers","Microsoft","Immediately scan all Exchange OWA servers for CVE-2026-42897 exploitation. Review OWA access logs for suspicious XSS payloads and unusual mailbox forwarding rules. If vulnerable, isolate affected servers and coordinate with Microsoft for emergency patching.",[19],"0ddc5039-7349-4c54-8b62-21ae7202fe73",null,[22],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Frussian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access\u002F","active","2026-08-02T08:06:26.255+00:00","2026-07-31T08:06:28.861186+00:00","2026-07-31T08:08:32.177219+00:00",[28],{"id":19,"title":6,"url":22}]