러시아 해커들이 Microsoft OWA 취약점을 이용해 정부와 기업을 공격하고 있다.
러시아의 위협 행위자들이 이제 패치된 Zimbra 취약점에 이어 Microsoft Outlook Web Access(OWA)의 취약점을 악용하여 공격을 감행하고 있다. 이 공격은 미국 및 유럽의 정부 기관뿐만 아니라 통신, 금융, 호스피탈리티, 항공 우주 산업을 목표로 하고 있다. 2026년 7월 22일부터 시작된 이 활동은 지속적으로 확인되고 있다.
Russian hackers exploit Microsoft OWA flaw to target government and corporate entities.
Russian threat actors have shifted from exploiting a patched vulnerability in Zimbra to targeting a flaw in Microsoft Outlook Web Access (OWA). Their attacks are focused on U.S. and European government entities, as well as sectors including telecommunications, financial services, hospitality, and aerospace. This activity has been observed since July 22, 2026, and continues to be monitored.