Feeds.4Sysops Russian Hackers Exploit OWA Flaw for Persistent Mailbox Access
Article Content
- •TA488 group exploits OWA flaw for persistent mailbox access.
- •OWAReaper implant allows access even after credential changes.
- •No current patches or mitigations available for affected systems.
The Russian-aligned TA488 group is exploiting a flaw in Microsoft Outlook Web Access (OWA) that allows them to maintain access to mailboxes even after password resets and device reimaging. This vulnerability enables the attackers to use an implant called OWAReaper, which grants them persistent server-side permissions by simply opening an email. The attack affects Microsoft Exchange servers and poses a significant risk to organizations that rely on OWA for email access. The exploitation method allows the attackers to bypass traditional security measures, making it challenging for organizations to secure their email environments. As of now, there are no specific patches or mitigations disclosed to address this vulnerability. Organizations are urged to monitor their OWA environments closely for unusual activity. The situation is critical as it involves state-sponsored actors and impacts enterprise-level security.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ta488 and OWAReaper in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
FamousSparrow Deploys SparroWocky Backdoor in Latin America The China-aligned cyberespionage group FamousSparrow has replaced its previous backdoor, SparrowDoor, with a new malware called SparroWocky, targeting governmental organizations in Latin America since August 2025. ESET Research attributes this campaign to a likely response to increased U.S. interests in the region.…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…