The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.
The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026.
Enterprise security company Proofpoint has attributed the activity to Laundry Bear (aka CL-STA-1114, TA488, UNK_PitStop, and Void Blizzard), which was recently attributed to the zero-day exploitation of CVE-2025-66376, an XSS flaw in Zimbra's Classic UI, since at least July 2025 before it was patched four months later.
In these attacks, the threat actors sent out messages from adversary-controlled Proton Mail accounts and from previously compromised addresses that triggered an exploit for CVE-2025-66376 as soon as the emails were viewed via a vulnerable version of Zimbra, ultimately resulting in the deployment of a JavaScript payload dubbed ZimReaper that's capable of harvesting 90 days of the victim's mail and other valuable data.












