HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Russian Hackers Exploit Microsoft OWA Flaw to Retain Mailbox Access After Credential Rotation

A Russian‑linked group leveraged a newly patched OWA vulnerability (CVE‑2026‑XXXX) to keep mailbox access after credentials were rotated, targeting government and high‑value sectors. The incident highlights gaps in SOC 2 logical‑access controls and the need for continuous session monitoring.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 thehackernews.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
5 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Russian Hackers Exploit Microsoft OWA Flaw to Retain Mailbox Access After Credential Rotation

What Happened — Researchers observed a Russian‑linked group leveraging a newly‑disclosed Microsoft Outlook Web Access (OWA) vulnerability to maintain persistent access to user mailboxes even after the compromised credentials were rotated. The campaign, active since 22 July 2026, targeted U.S. and European government agencies and organizations in telecommunications, financial services, hospitality, and aerospace.

Why It Matters for Compliance & Audit Readiness

  • The attack demonstrates how a single application‑level flaw can bypass credential‑rotation controls that are a core requirement of SOC 2 CC 6.2 (Logical Access).
  • Continuous monitoring of privileged‑access sessions and immutable audit logs is essential to prove that access revocation actually took effect.
  • Mapping this scenario to Verisq’s SOC 2 Access Controls capability provides the evidence‑collection framework needed for a defensible audit trail.

Who Is Affected – Government, telecom, finance, hospitality, and aerospace entities that expose OWA to external users.

Recommended Actions

  • Verify that all OWA servers are patched to the latest Microsoft security update (released 24 July 2026).
  • Enable MFA for OWA and enforce session‑termination policies that invalidate active tokens on credential change.
  • Deploy continuous session‑monitoring tools that capture authentication events and retain them for the SOC 2 audit period.
  • Review and update your logical‑access policies to include “post‑rotation token revocation” as a control objective.

Technical Notes – The vulnerability (CVE‑2026‑XXXX) allowed an attacker with a valid mailbox token to request a new token after password change, effectively bypassing the rotation. Exploitation required a valid OWA session and leveraged an authentication‑bypass flaw in the token‑refresh endpoint. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →