Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Summary
Russian state hackers from the group TA488 are exploiting a serious security flaw in Microsoft Outlook’s Exchange Server. The flaw allows attackers to secretly install malware when a victim opens an email in Outlook Web Access, giving hackers long-lasting access to email accounts and sensitive information.Key Facts
- The hacker group TA488 works for the Kremlin and targets unpatched Exchange Server machines.
- They exploit a security weakness called CVE-2026-42897, a type of cross-site scripting (XSS) flaw.
- Microsoft patched this vulnerability in July after providing initial guidance in May.
- The malware, named OWAReaper by researchers, is activated simply by opening an email in Outlook Web Access (OWA).
- OWAReaper captures saved passwords and email tokens to gain persistent access to victims’ mailboxes.
- This backdoor remains active on the server and cannot be removed just by changing passwords or reinstalling the user’s device.
- Proofpoint and the U.S. National Security Agency issued warnings about this and similar ongoing attacks exploiting email services.
- Users are advised to check for unauthorized access, remove unwanted permissions, and apply Microsoft’s updates to secure their systems.
Read the Full Article
This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.