:

RUSSIAN HACKERS EXPLOIT EXCHANGE ZERO-DAY

AI DESK1 MIN READ
WED, JUL 29, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Russian state-sponsored group Laundry Bear is leveraging an Exchange Outlook Web Access vulnerability to deploy OWAReaper, a sophisticated backdoor enabling persistent mailbox access.

The threat actors, also tracked as Void Blizzard, are distributing the malware through targeted email campaigns. OWAReaper provides attackers long-term access to compromised Exchange servers, allowing them to harvest sensitive communications and maintain presence within victim networks. The zero-day vulnerability affects Exchange OWA, a web-based email interface used by organizations globally. Laundry Bear's targeting suggests interest in espionage and data theft from government and enterprise sectors. Microsoft has not yet released patches for the vulnerability. Organizations running vulnerable Exchange versions should review mailbox access logs for suspicious activity and consider implementing additional email security controls. Security researchers recommend prioritizing OWA server isolation and monitoring for unusual login patterns until patches become available. This marks another significant cyber operation attributed to Russian state actors in 2024, following increased activity targeting critical infrastructure and government networks.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.

2H AGOSecurity Desk

A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.

4H AGOIndustry Desk

A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.

9H AGOIndustry Desk

Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.

12H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.