# Russian Hackers Use Microsoft OWA Flaw to Retain Mailbox Access After Password Reset

Russian hackers exploited a vulnerability in Microsoft Outlook Web Access (OWA) to maintain access to email accounts even after credentials were rotated. The flaw allowed them to retain session tokens, bypassing security measures such as password changes. This incident underscores persistent risks to enterprise email systems from sophisticated state-sponsored threat actors.

**Importance:** 4/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html) — Thu, 30 Jul 2026 13:10:48 +0530