Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Russian Hackers Exploit Microsoft OWA Flaw, Bypassing Security Measures to Maintain Access to Mailboxes

A sophisticated cyber attack uncovered recently has left security experts concerned about the potential for malicious actors to evade even the most robust security measures. Russian hackers have been exploiting a previously unknown vulnerability in Microsoft’s Outlook Web Application (OWA), allowing them to maintain unauthorized access to user mailboxes even after their credentials have been rotated.

The exploit, which leverages an issue with how OWA handles certain types of authentication requests, enables attackers to bypass the very security protocols designed to protect against this type of threat. By manipulating these requests, hackers can create a “backdoor” into a user’s mailbox, permitting them to snoop on emails, steal sensitive information, or even take control of the account entirely.

OWA is a widely used web-based email client that integrates seamlessly with Microsoft Exchange Server. It allows users to access their email accounts from any internet-connected device without the need for additional software downloads. However, this convenience comes at a cost: OWA’s reliance on JavaScript and other web technologies makes it vulnerable to various types of attacks, including cross-site scripting (XSS) and cross-site request forgery (CSRF).

The Russian hackers’ exploit takes advantage of an issue with how OWA handles CSRF tokens, which are designed to prevent attackers from tricking users into performing unauthorized actions. By manipulating these tokens, the hackers can effectively “bypass” the security measures in place, allowing them to maintain access to user mailboxes even after the credentials have been rotated.

This attack highlights a pressing concern: that relying solely on traditional security measures may not be enough to protect against emerging threats. As AI-powered threat detection tools become increasingly prevalent, they are also uncovering new vulnerabilities in software systems that were previously thought secure. The Microsoft OWA exploit serves as a stark reminder of the need for constant vigilance and proactive security measures.

For organizations using OWA or any other web-based email client, it is essential to remain vigilant and take immediate action to mitigate this risk. This includes regularly updating software and plugins, implementing robust access controls, and monitoring user accounts for suspicious activity. By taking these steps, you can reduce the likelihood of falling prey to such attacks and maintain a secure online environment for your users.


Source: The Hacker News — 2026-07-30