Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Nitecore’s latest power bank is the lightest and most compact yet

    This One-of-a-Kind LG 6K Professional Monitor Just Dropped to a Record Low Price

    Today’s NYT Strands Hints, Answers and Help for Aug. 8 #888

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»Chatbots»Max-severity Exchange server flaw under active exploitation by Kremlin hackers
    Chatbots

    Max-severity Exchange server flaw under active exploitation by Kremlin hackers

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Max-severity Exchange server flaw under active exploitation by Kremlin hackers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Russian state hackers are using a maximum-severity vulnerability in Microsoft’s Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday.

    The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday. Proofpoint and the National Security Agency jointly warned last week that the group, also tracked as Laundry Bear and Void Blizzard, had been carrying out similar attacks by exploiting a zero-day vulnerability in an email service from Zimbra. The revelation that TA488 is also exploiting the Exchange Server vulnerability to install advanced malware when a user does nothing other than open an email sent to an Outlook Web Access (OWA) account has elevated the group’s profile and assessments of its abilities.

    Doubling down

    “TA488 is doubling down on the use of ‘half-click’ exploits—where opening the email is enough to trigger compromise—with significantly improved loading mechanisms, techniques, and malware, signaling an improvement in the group’s tradecraft and capability,” Proofpoint researchers wrote. “This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA.”

    The vulnerability, tracked as CVE-2026-42897, is a cross-site-scripting vulnerability, usually abbreviated as XSS, that Microsoft provided mitigation advice for in May and patched in July. Microsoft gave it a maximum severity rating. The vulnerability, which stems from a failure to properly filter HTML embedded in an email, allows malicious JavaScript execution. Proofpoint said that TA488 may have exploited it as a zero-day.

    The malicious JavaScript installs a novel, custom-built browser extension that gives attackers persistent access to victims’ OWA accounts. Proofpoint said it was the most sophisticated backdoor the company has ever seen delivered through a half-click exploit. The company has named it OWAReaper.

    active exchange exploitation flaw hackers Kremlin Maxseverity server
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleTim Cook passes the baton in Apple’s Q3 2026 earnings call
    Next Article Don’t Just “Throw Adam at It”: Misunderstanding Adam Will Cost You
    • Website

    Related Posts

    Chatbots

    Grab the entire Lord of the Rings trilogy on 4K Blu-ray for $50

    Chatbots

    Microsoft Edge is about to lock out older ad blockers, just like Chrome did

    Chatbots

    Volkswagen plans to win America back with a pickup, report says

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Nitecore’s latest power bank is the lightest and most compact yet

    0 Views

    This One-of-a-Kind LG 6K Professional Monitor Just Dropped to a Record Low Price

    0 Views

    Today’s NYT Strands Hints, Answers and Help for Aug. 8 #888

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Nitecore’s latest power bank is the lightest and most compact yet

    0 Views

    This One-of-a-Kind LG 6K Professional Monitor Just Dropped to a Record Low Price

    0 Views

    Today’s NYT Strands Hints, Answers and Help for Aug. 8 #888

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.