俄黑客利用 Exchange Server 严重漏洞植入 OWAReaper 后门
原标题:Max-severity Exchange server flaw under active exploitation by Kremlin hackers
AI 摘要
俄罗斯国家黑客组织 TA488 正在利用微软 Outlook Exchange Server 中的一个最大严重性漏洞(CVE-2026-42897)攻击未修补的机器,窃取凭证和机密信息。该漏洞为跨站脚本漏洞,用户只需打开邮件即可触发恶意 JavaScript 执行,最终安装名为 OWAReaper 的新型浏览器植入程序,实现对 Outlook Web Access 账户的持久访问。Proofpoint 和 NSA 此前已联合警告该组织利用 Zimbra 零日漏洞进行类似攻击。
正文节选
Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday. Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Bli