OWA Mailboxes Stay Open After Password Resets

A malicious OWA message can leave attackers inside the mailbox after the password is changed and the laptop is wiped. The trap runs in the authenticated webmail session, then uses browser and server-side persistence so the account stays exposed long after the first email is opened. Proofpoint says TA488, also tracked as Laundry Bear and Void Blizzard, started exploiting CVE-2026-42897 in on-premises Exchange OWA on July 22. The campaign targeted government, telecom, financial, hospitality, and aerospace organizations, and used a previously unknown JavaScript implant, OWAReaper, to steal mail and credentials and survive credential rotation and device re-imaging. The practical break is that normal cleanup can miss the real foothold. If the implant has already turned mailbox permissions or stored state into a trust anchor, patching the bug does not by itself close the account to an authenticated insider or to the operator who is still riding those tokens.

Part of the PlainSec briefing for 2026-07-29

Sources