Russian hackers have been exploiting a previously unknown vulnerability in Microsoft Outlook Web Access (OWA) to maintain unauthorized access to email accounts, even after users have rotated their credentials. The flaw, which affects all versions of OWA up to and including the latest iteration, allows attackers to bypass security measures put in place by organizations to limit access to email accounts.
The hacking group, identified as APT28 (also known as Fancy Bear), has been using this exploit to infiltrate high-profile targets’ email systems. Once inside, they can snoop on sensitive communications and even modify emails without being detected. The vulnerability works by allowing hackers to create a persistent session on the OWA server, which is not terminated when the user logs out or changes their password.
The exploit’s effectiveness lies in its ability to evade detection. When users rotate their credentials, the OWA system typically closes any existing sessions and establishes new ones. However, APT28’s code allows them to create a “hidden” session that remains active even after the user has changed their password. This means that hackers can maintain access to email accounts without being locked out, making it challenging for organizations to detect and mitigate the attack.
This vulnerability highlights the importance of keeping software up-to-date, as Microsoft had issued patches to address similar issues in previous versions of OWA. However, this new exploit targets a previously unknown weakness that has not been addressed by Microsoft’s security updates. This is particularly concerning given the widespread adoption of OWA across various industries and organizations.
The exploitation of this vulnerability underscores the evolving threat landscape in which AI-powered attacks are becoming increasingly sophisticated. As AI models become more adept at discovering software vulnerabilities, it’s crucial for organizations to prioritize proactive measures such as regular security audits, automated patch management, and employee education on cybersecurity best practices.
To protect against similar exploits, users should ensure that their organization is running the latest version of OWA with all recommended security patches applied. Additionally, administrators should conduct thorough risk assessments to identify potential vulnerabilities in their email systems and implement robust access controls to limit unauthorized access. By staying vigilant and proactive, organizations can mitigate the risks associated with software vulnerabilities and prevent malicious actors from exploiting them.
Source: The Hacker News — 2026-07-30