Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-30 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Max-Severity Exchange Server Flaw Under Active Exploitation by Kremlin Hackers

Summary

Ars Technica's Dan Goodin reported a maximum-severity Microsoft Exchange vulnerability under active exploitation by Kremlin-aligned hackers. The exploit provides persistent server access that survives credential rotation and disk re-imaging.

Key Details

  • Date: 2026-07-30
  • Source: Ars Technica
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Threat Actor: Kremlin-aligned hackers (Russian state-sponsored)
  • Affected Product: Microsoft Exchange Server
  • Severity: Maximum severity
  • Capability: Persistent server access surviving credential rotation and disk re-imaging
  • Status: Active exploitation in the wild

Significance

The persistence capability (surviving credential rotation and disk re-imaging) makes this particularly dangerous for enterprise environments. The flaw and its exploitation were disclosed by researchers tracking Russian state-sponsored cyber operations.

Sources