Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Summary

Russian threat actors are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain mailbox access even after credentials have been rotated. This campaign, which began in July 2026, targets various sectors including government, telecommunications, finance, hospitality, and aerospace in the U.S. and Europe.

IFF Assessment

FOE

The exploitation of a vulnerability that allows attackers to bypass credential rotation significantly compromises account security, representing bad news for defenders.

Defender Context

This campaign highlights the persistent threat of state-sponsored actors and the critical need for organizations to monitor for sophisticated post-exploitation techniques. Defenders should ensure timely patching of all Microsoft OWA components and implement robust detection and response mechanisms to identify and mitigate unauthorized access, especially in the face of credential rotation bypass.

Read Full Story →