Frequency
7
occurrences
First Seen
July 23, 2026
Last Seen
July 30, 2026
Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Russian Hackers Exploit OWA Flaw for Persistent Mailbox Access
The Russian-aligned TA488 group is exploiting a flaw in Microsoft Outlook Web Access (OWA) that allows them to maintain access to mailboxes even after password resets and device reimaging. This vulnerability enables the…
2 articles · Updated July 30, 2026 -
TA488 Exploits Outlook Web Access CVE-2026-42897 in New Campaign
TA488 has launched a campaign exploiting CVE-2026-42897, a cross-site scripting flaw in Outlook Web Access (OWA). This vulnerability, disclosed by Microsoft on May 14, 2026, allows attackers to deploy a persistent…
3 articles · Updated July 30, 2026
Recent Intelligence Reports
- Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover — Csoonline · July 30, 2026
- Russian hackers use OWAReaper to keep Microsoft OWA access after resets — Feeds.4Sysops · July 30, 2026
- TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch — Cybersecuritynews · July 30, 2026
- TA488 Exploits Outlook Half — Gbhackers · July 30, 2026
- Russian attackers exploit zero-click vulnerability in Zimbra — Heise.De · July 24, 2026
- Russian spies exploit unpatched Zimbra flaw to steal NATO member emails — Cybernews · July 24, 2026
- TA488 Targets Zimbra Mailservers with Half — Proofpoint · July 23, 2026