Max-severity Exchange server flaw under active exploitation by Kremlin hackers
2026-07-31T08:51:38Z•0cb27fafe879316e9a18d71e7244b08ccdf1fd3cba16c03c4e5de5c1167f53e3
AI agentsAI securityClickFixHugging FaceKremlin-linked threat actorsLinuxMicrosoft Exchange ServerRussian state-sponsored activitySecure BootWindowsactive exploitationbotnetcryptographymacOS infostealerpersistent accessprompt injectionransomwarerouter targetingsoftware supply chainvirtual machine escapezero-day
What happened
Ars Technica security coverage highlights active exploitation of a maximum-severity Microsoft Exchange Server vulnerability by Kremlin-linked hackers, with persistent access surviving credential rotation and disk re-imaging. Other reports cover Windows and Secure Boot zero-days, Russian state-sponsored router targeting and ClickFix campaigns, ransomware, macOS infostealers, Linux guest VM escapes, AI-agent and prompt-injection risks, and vulnerabilities in AI and software supply-chain ecosystems.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 0cb27fafe879316e9a18d71e7244b08ccdf1fd3cba16c03c4e5de5c1167f53e3
- Enrichment time
- 2026-07-31T08:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.