State‑Linked Laundry Bear Exploits Zero‑Day in Microsoft Outlook Web Access to Harvest Emails and Credentials
What Happened — Researchers at Proofpoint disclosed that the Russian‑state‑linked APT group Laundry Bear (TA488/Void Blizzard) leveraged a previously unknown zero‑day in Microsoft Outlook Web Access (CVE‑2026‑42897) and a known flaw in Zimbra Collaboration Suite to deliver a sophisticated JavaScript implant called OWAReaper. The chain can start with a “half‑click” email, giving the attackers persistent access to victim mailboxes and credentials.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a failure to enforce access‑control safeguards (least‑privilege, MFA, session monitoring) that SOC 2 CC6.1 requires.
- Continuous evidence of patch management and credential‑use monitoring is essential to demonstrate due diligence during a SOC 2 audit.
- Security‑awareness training that covers half‑click exploits helps satisfy the SOC 2 CC1.2 requirement for employee security awareness.
Who Is Affected — Government agencies, telecommunications, financial services, hospitality, aerospace, and any organization using Microsoft OWA or Zimbra webmail.
Recommended Actions
- Verify that all OWA and Zimbra installations are patched to the latest releases; apply Microsoft’s July remediation guidance immediately.
- Enforce multi‑factor authentication and conditional access for all webmail accounts; log and review privileged sign‑ins.
- Deploy email‑gateway sandboxing and anti‑phishing controls that detect malicious JavaScript and half‑click techniques.
- Update security‑awareness curricula to include “half‑click” exploitation scenarios and reinforce safe email‑handling practices.
Source: The Record – Laundry Bear’s webmail hackers had more in store after February
Technical Notes — The OWA bug (CVE‑2026‑42897) was publicly disclosed and patched in May 2026; Proofpoint observed a novel JavaScript backdoor (OWAReaper) delivered via half‑click email exploits. No CVSS score is publicly disclosed yet. Source: same as above