HIGH
Russian State Hackers 'Laundry Bear' Exploiting Microsoft Outlook Web Access Bug
Researchers say the Russia-linked hacking group tracked as Laundry Bear has begun exploiting a vulnerability in Microsoft Outlook Web Access. The group was previously tied to a February campaign against webmail targets; the new activity indicates they retained capability beyond what was disclosed at the time. The report does not specify a CVE or patch status for the exploited OWA bug. Organizations exposing Outlook Web Access externally should review authentication logs for anomalous access consistent with state-linked activity.