Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Summary
Russian threat actors are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain mailbox access even after credentials have been rotated. This campaign, which began in July 2026, targets various sectors including government, telecommunications, finance, hospitality, and aerospace in the U.S. and Europe.
IFF Assessment
The exploitation of a vulnerability that allows attackers to bypass credential rotation significantly compromises account security, representing bad news for defenders.
Defender Context
This campaign highlights the persistent threat of state-sponsored actors and the critical need for organizations to monitor for sophisticated post-exploitation techniques. Defenders should ensure timely patching of all Microsoft OWA components and implement robust detection and response mechanisms to identify and mitigate unauthorized access, especially in the face of credential rotation bypass.