Exchange Server critical flaw exploited by Russian hackers

Original: Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Why This Matters

Critical Exchange Server flaws remain a top vector for state-sponsored espionage against enterprise and government targets.

A maximum-severity vulnerability in Microsoft Exchange Server is being actively exploited by Kremlin-linked threat actors to install backdoors on unpatched networks, according to reporting by Ars Technica.

Ars Technica reports that a maximum-severity flaw in Microsoft Exchange Server is under active exploitation by Russian state-sponsored hackers. The threat actors are leveraging the vulnerability to deploy backdoors on networks that have not yet applied available patches. The attack campaign is attributed to Kremlin-linked groups known for targeting enterprise email infrastructure. Exchange Server vulnerabilities have historically been high-value targets due to the platform's widespread use in corporate and government environments. Organizations running unpatched Exchange deployments are urged to apply Microsoft's security updates immediately to mitigate exposure. No further technical details about the specific CVE identifier or exploitation method were available from the source at time of publication.

Source

arstechnica.com — Read original →