< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 9 sources · 1 days · First seen · Last updated

Categories: TECHNOLOGY

TA488 OWAReaper Outlook Web Access exploit

Entities: Outlook Web Access · TA488 · CVE-2026-42897 · Outlook Web Access · Microsoft

Overview

In late July 2026, the Russia‑aligned cyber‑espionage group TA488 (also known as Laundry Bear or Void Blizzard) was observed exploiting a critical cross‑site scripting flaw (CVE‑2026‑42897) in Microsoft Outlook Web Access. The “half‑click” exploit required only opening a crafted email, allowing the group to install the OWAReaper backdoor, which persists in the browser session and retains Owner‑level permissions even after password changes or device re‑imaging. The campaign, first reported on July 22, targeted government agencies, telecoms, financial services, hospitality and aerospace firms across the United States and Europe. Microsoft had disclosed the vulnerability in May and issued a patch in June, but the exploit was active before the public fix.

A follow‑up report the next day reiterated the same exploit chain, confirming that TA488 had been abusing the flaw since May 2026. While the focus remained on the OWAReaper threat, the report also noted a separate cloud‑based data breach at biotech firm Amgen attributed to the ShinyHunters group, underscoring a broader rise in sophisticated cyber‑attacks on enterprise and healthcare systems.

Timeline

  1. 6 days ago

    [TECHNOLOGY] 2 sources
    Microsoft OWA Exploit and Amgen Data Breach Signal Growing Cyber Threats

    New OWAReaper exploit targets Microsoft Outlook Web Access via CVE‑2026‑42897, while Amgen reports a cloud breach stealing patient data, highlighting rising cyber threats.

  2. 7 days ago

    [TECHNOLOGY] 8 sources
    TA488 exploits Outlook Web Access zero‑day, adds OWAReaper backdoor

    Russia‑linked TA488 used a half‑click OWA zero‑day (CVE‑2026‑42897) to install the persistent OWAReaper backdoor, targeting US and European organisations; Microsoft has patched the flaw and admins should revoke

Sources

bild.de · borncity.com · cybersecuritynews.com · dev.to · it-boltwise.de · map.simonsarris.com · solidsoftwaretools.com · theregister.co.uk · welivesecurity.com