Russian state-sponsored hackers are actively exploiting an unpatched zero-day in Microsoft Exchange's Outlook Web Access to maintain long-term, persistent access to victim mailboxes, with no official Microsoft patch yet available.
BleepingComputer and The Hacker News are both reporting that Russian threat actors are exploiting a zero-day vulnerability in Microsoft Exchange's Outlook Web Access to gain long-term, persistent access to victim mailboxes. This is an active exploitation campaign against unpatched infrastructure, not a theoretical research finding — the attackers are already inside and staying inside.
This is the third or fourth act of a play Exchange admins have watched before: ProxyLogon, ProxyShell, and prior OWA-facing bugs all followed the same script — a nation-state actor gets early access to a flaw in the internet-facing Exchange stack, uses it for quiet, long-dwell espionage against high-value mailboxes, and the vulnerability only becomes public once defenders notice anomalous mail access months later. Exchange OWA is a perennial target precisely because it's the one Microsoft service organizations are most reluctant to take offline — it's how executives check email from a phone at 11pm — which makes it a durable beachhead for state actors who prize persistence over speed.
The SAL read: if your organization runs on-prem or hybrid Exchange with OWA exposed to the internet, treat every mailbox as potentially already read and start hunting for anomalous access patterns now, rather than waiting for Microsoft's patch and advisory to tell you where to look.
Until an official patch lands, the practical move is to tighten what you control immediately: enforce MFA on all OWA logins, restrict OWA access by IP or VPN where feasible, and have someone competent review Exchange access and mailbox audit logs for unusual mail-forwarding rules or impersonation tokens — the classic fingerprints of this style of long-dwell mailbox compromise.
It's an unpatched flaw in Microsoft Exchange's Outlook Web Access that Russian threat actors are actively exploiting, according to BleepingComputer and The Hacker News. Attackers are using it to gain long-term, persistent access to victim mailboxes. There is no official Microsoft patch or advisory available yet.
Yes. This is described as an active exploitation campaign against unpatched infrastructure, not a theoretical research finding. The attackers are already inside targeted mailboxes and staying inside for long-dwell espionage.
The article calls this the third or fourth act of a familiar play, following the same script as ProxyLogon, ProxyShell, and prior OWA-facing bugs. A nation-state actor gets early access to an Exchange flaw, uses it for quiet long-dwell espionage against high-value mailboxes, and the vulnerability only becomes public once defenders notice anomalous mail access months later.
The article recommends enforcing MFA on all OWA logins, restricting OWA access by IP or VPN where feasible, and having someone competent review Exchange access and mailbox audit logs for unusual mail-forwarding rules or impersonation tokens. Organizations running on-prem or hybrid Exchange with OWA exposed to the internet should treat every mailbox as potentially already read and start hunting for anomalous access patterns now rather than waiting for Microsoft's patch.
OWA is a perennial target because it's the one Microsoft service organizations are most reluctant to take offline, since it's how executives check email from a phone at 11pm. That reluctance to disable it makes OWA a durable beachhead for state actors who prize persistence over speed.
The article points to unusual mail-forwarding rules and impersonation tokens found in Exchange access and mailbox audit logs as the classic fingerprints of this style of long-dwell mailbox compromise. Reviewing those logs for anomalous access patterns is the recommended detection method.