Microsoft Exchange Zero-Day Under Attack: One Email Hijacks OWA episode artwork

EPISODE · Jun 5, 2026 · 9 MIN

Microsoft Exchange Zero-Day Under Attack: One Email Hijacks OWA

from Plaintext with Rich · host Rich Greene

It's Monday morning. You open the third email of the day. Nothing visible happens, but in the background, an attacker just borrowed the proof you were logged in.Episode 28 of Plaintext with Rich is a hot take on CVE-2026-42897, the Microsoft Exchange Server zero-day under active exploitation right now. We break down what cross-site scripting actually does inside Outlook Web Access, why session hijacking is more dangerous than the underlying bug, and how a single crafted email becomes business email compromise. We look at the on-premises versus Exchange Online divide, why ProxyLogon and ProxyShell aren't ancient history yet, and what CISA's Known Exploited Vulnerabilities catalog listing and the May 29 federal deadline mean for everyone else. The episode closes with a Plaintext Starter Kit of four moves any on-prem Exchange team should make this week.If you run on-prem Exchange, support someone who does, or you've been putting off the migration conversation, this one is for you.Ten minutes. One topic. No panic.Is there a topic/term you want me to discuss next? Text me!!YouTube more your speed? → https://links.sith2.com/YouTube  Apple Podcasts your usual stop? → https://links.sith2.com/Apple  Neither of those? Spotify’s over here → https://links.sith2.com/Spotify  Prefer reading quietly at your own pace? → https://links.sith2.com/Blog  Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord  Follow the human behind the microphone → https://links.sith2.com/linkedin  Need another way to reach me? That’s here → https://linktr.ee/rich.greene

Episode metadata supplied by the publisher feed · Published Jun 5, 2026

Embed this episode

It's Monday morning. You open the third email of the day. Nothing visible happens, but in the background, an attacker just borrowed the proof you were logged in. Episode 28 of Plaintext with Rich is a hot take on CVE-2026-42897, the Microsoft Exchange Server zero-day under active exploitation right now. We break down what cross-site scripting actually does inside Outlook Web Access, why session hijacking is more dangerous than the underlying bug, and how a single crafted email becomes busines...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

Microsoft Exchange Zero-Day Under Attack: One Email Hijacks OWA

0:00 9:03

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Plaintext with Rich?

This episode is 9 minutes long.

When was this Plaintext with Rich episode published?

This episode was published on June 5, 2026.

Can I download this Plaintext with Rich episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!