#OutlookWebAccess
Ohne auf Details einzugehen: erneut erweisen sich Microsoft-Systeme als sicherheitskritisch, wie das @bsi informiert. Der Verbund älterer, aber vielgenutzter #ExchangeServer und dem aus dem Internet erreichbaren #outlookwebaccess scheint angreifbar zu sein. #DigitaleSouveränität […]
Original post on nrw.social
nrw.social
August 28, 2026 at 8:20 AM
Ohne auf Details einzugehen: erneut erweisen sich Microsoft-Systeme als sicherheitskritisch, wie das @bsi informiert. Der Verbund älterer, aber vielgenutzter #exchangeserver und dem aus dem Internet erreichbaren #outlookwebaccess scheint angreifbar zu sein. Nach meinem Wissensstand ist diese […]
Original post on drk.network
drk.network
August 28, 2026 at 8:26 AM
📰 Hacker Rusia Eksploitasi Zero-Day Exchange OWA untuk Mempertahankan Akses ke Kotak Email Korban

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/03/zero-day-exchange-owa-owareaper-rusia/

#apt
##apta#keamananSibera#malwareo#microsoftExchangeo#outlookWebAccess##owaa#rusia-#zero
August 3, 2026 at 6:52 AM
Russian hackers are exploiting a new Exchange OWA XSS flaw in half-click email attacks, deploying OWAReaper for long-term mailbox access across U.S. and European government and industry targets. #Russia #Exchange #OWAReaper
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Laundry Bear, also tracked as Void Blizzard and TA488, is using the CVE-2026-42897 Outlook Web Access XSS flaw in half-click email attacks to deliver the OWAReaper backdoor. The campaign targets government and industry organizations across the U.S. and Europe and uses advanced persistence, credential theft, and multi-channel command-and-control to maintain long-term mailbox access. #LaundryBear #VoidBlizzard #TA488 #CVE-2026-42897 #OWAReaper #MicrosoftExchange #OutlookWebAccess
www.hendryadrian.com
July 30, 2026 at 1:45 AM
TA488 is exploiting CVE-2026-42897 in Outlook Web Access to deploy OWAReaper, targeting government, telecom, finance, hospitality, and aerospace sectors with stealthy persistence and exfiltration. #USA #TA488 #OutlookWebAccess
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
TA488 launched a July 2026 campaign exploiting CVE-2026-42897 in Outlook Web Access to deliver the browser-based implant OWAReaper against government, telecommunications, finance, hospitality, and aerospace targets. OWAReaper provides stealthy persistence, credential theft, command execution, and exfiltration through HTTPS or DNS, using infrastructure such as acocdn[.]com, asecdns[.]com, dnsrecursive[.]eu, and tdndns[.]com. #TA488 #OWAReaper...
www.hendryadrian.com
July 29, 2026 at 10:45 AM
📰 Microsoft Akan Hentikan Dukungan OWA Light di Exchange Server

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/07/10/microsoft-retire-owa-light-exchange-server/

#ema
il#emaila#exchangea#exchangeServero#microsofto#microsoftExchangeo#outlookOnTheWebo#outlookWebAccessi#owaLighte#server href="/hashtag/te" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#te
July 10, 2026 at 3:43 AM