HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High ThreatIntel

State‑Linked Laundry Bear Exploits Zero‑Day in Microsoft Outlook Web Access to Harvest Emails and Credentials

Laundry Bear leveraged a zero‑day (CVE‑2026‑42897) in Microsoft Outlook Web Access and a flaw in Zimbra to deliver a sophisticated JavaScript backdoor, targeting government and high‑value sectors. The episode underscores the need for robust access‑control policies and continuous audit evidence in SOC 2 programs.

LiveThreat™ Intelligence · 📅 July 29, 2026· 📰 therecord.media
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
5 sector(s)
Actions
4 recommended
📰
Source
therecord.media

State‑Linked Laundry Bear Exploits Zero‑Day in Microsoft Outlook Web Access to Harvest Emails and Credentials

What Happened — Researchers at Proofpoint disclosed that the Russian‑state‑linked APT group Laundry Bear (TA488/Void Blizzard) leveraged a previously unknown zero‑day in Microsoft Outlook Web Access (CVE‑2026‑42897) and a known flaw in Zimbra Collaboration Suite to deliver a sophisticated JavaScript implant called OWAReaper. The chain can start with a “half‑click” email, giving the attackers persistent access to victim mailboxes and credentials.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a failure to enforce access‑control safeguards (least‑privilege, MFA, session monitoring) that SOC 2 CC6.1 requires.
  • Continuous evidence of patch management and credential‑use monitoring is essential to demonstrate due diligence during a SOC 2 audit.
  • Security‑awareness training that covers half‑click exploits helps satisfy the SOC 2 CC1.2 requirement for employee security awareness.

Who Is Affected — Government agencies, telecommunications, financial services, hospitality, aerospace, and any organization using Microsoft OWA or Zimbra webmail.

Recommended Actions

  • Verify that all OWA and Zimbra installations are patched to the latest releases; apply Microsoft’s July remediation guidance immediately.
  • Enforce multi‑factor authentication and conditional access for all webmail accounts; log and review privileged sign‑ins.
  • Deploy email‑gateway sandboxing and anti‑phishing controls that detect malicious JavaScript and half‑click techniques.
  • Update security‑awareness curricula to include “half‑click” exploitation scenarios and reinforce safe email‑handling practices.

Source: The Record – Laundry Bear’s webmail hackers had more in store after February

Technical Notes — The OWA bug (CVE‑2026‑42897) was publicly disclosed and patched in May 2026; Proofpoint observed a novel JavaScript backdoor (OWAReaper) delivered via half‑click email exploits. No CVSS score is publicly disclosed yet. Source: same as above

📰 Original Source
https://therecord.media/russia-hackers-outlook-webmail-malware

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →