Max-severity Exchange server flaw under active exploitation by Kremlin hackers

2026-07-31T08:51:38Z0cb27fafe879316e9a18d71e7244b08ccdf1fd3cba16c03c4e5de5c1167f53e3
AI agentsAI securityClickFixHugging FaceKremlin-linked threat actorsLinuxMicrosoft Exchange ServerRussian state-sponsored activitySecure BootWindowsactive exploitationbotnetcryptographymacOS infostealerpersistent accessprompt injectionransomwarerouter targetingsoftware supply chainvirtual machine escapezero-day

What happened

Ars Technica security coverage highlights active exploitation of a maximum-severity Microsoft Exchange Server vulnerability by Kremlin-linked hackers, with persistent access surviving credential rotation and disk re-imaging. Other reports cover Windows and Secure Boot zero-days, Russian state-sponsored router targeting and ClickFix campaigns, ransomware, macOS infostealers, Linux guest VM escapes, AI-agent and prompt-injection risks, and vulnerabilities in AI and software supply-chain ecosystems.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
0cb27fafe879316e9a18d71e7244b08ccdf1fd3cba16c03c4e5de5c1167f53e3
Enrichment time
2026-07-31T08:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.