Exploited in the wild Outlook Web Access (OWA) TA488 web-app Microsoft Laundry Bear
Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
CVE Tools coverage
A Russian-affiliated hacking group, Laundry Bear (also known as Void Blizzard or TA488), is actively exploiting a cross-site scripting vulnerability in Microsoft Exchange (CVE-2026-42897) to deploy a sophisticated backdoor called OWAReaper. The exploit targets government and private sector organizations in the U.S. and Europe through seemingly innocuous emails that trigger malicious code when opened. Once activated, the malware steals credentials, grants unauthorized access to mailboxes, and persists across device reimages. Microsoft issued a patch for this flaw in June 2026, but attackers had already been using it as a zero-day since March. Organizations are urged to apply the fix immediately and scan for signs of compromise.