What happened
Beginning July 22, 2026, a Russian threat group previously tied to Zimbra exploitation pivoted to a newly identified flaw in Microsoft Outlook Web Access, using it to maintain persistent mailbox access even after targeted organizations rotated compromised credentials. Victims span U.S. and European government agencies alongside firms in telecommunications, finance, hospitality, and aerospace. Separately, LG Electronics USA announced plans to pull smart TV applications from its webOS store that silently enroll televisions as residential proxy nodes — a practice researchers found affects more than 42 percent of available apps, allowing unknown third parties to route internet traffic through household devices without owner awareness.
Why it matters for your business
The OWA exploitation is particularly damaging because it defeats one of the most common incident-response reflexes: forcing a password reset. Organizations that believe they have contained an email breach by rotating credentials may still have an active adversary reading communications, exfiltrating data, or staging lateral movement. Security teams should audit OWA configurations, apply available patches immediately, and treat mailbox access logs as a primary indicator of compromise rather than a secondary check. The LG proxy finding carries its own enterprise risk: corporate networks that permit personal or shared smart TVs — common in hotel rooms, lobbies, and remote work environments — may be inadvertently providing threat actors with a trusted residential IP address, complicating traffic-analysis and geo-blocking defenses.
What to watch next
Microsoft has not yet publicly confirmed a full patch timeline for all affected OWA configurations, so organizations should monitor advisories closely and consider temporarily restricting OWA exposure to VPN-authenticated sessions. On the smart TV front, LG's enforcement posture will be tested by how swiftly it audits its developer ecosystem and whether other platform operators — Samsung, Roku, Amazon — follow with similar bans. Regulatory scrutiny of consumer IoT devices as proxy infrastructure is likely to intensify, particularly in the EU under the Cyber Resilience Act framework.
