Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
2026-09-01T13:23:22Z•37684a0bf5b3a50b12a606d70012fb6f9c0aef4192bb98e2353c0ff0559fd5b1
ATM jackpottingCisco IOS XRClickFixGRE tunnelMicrosoft ExchangePaperCutPowerShellRhysidaTerminalFixauthentication bypasscryptocurrency exploitdata theftespionageinfostealermailbox hijackingransomwarereverse tunnelsrouter compromisesession hijackingsocial engineeringvulnerability managementzero-day exploitation
What happened
BleepingComputer reports multiple cybersecurity incidents and advisories, including nearly 22,000 internet-exposed Microsoft Exchange servers vulnerable to a high-severity authentication bypass enabling mailbox hijacking, exploitation of recently patched PaperCut zero-days for data theft, TerminalFix social engineering attacks delivering PowerShell reverse tunnels, Cisco router compromise for espionage, ransomware-related data theft, infostealer theft of Claude sessions, and major cryptocurrency and ATM attacks. The collection also includes service outages, software defects, law-enforcement,แ్
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 37684a0bf5b3a50b12a606d70012fb6f9c0aef4192bb98e2353c0ff0559fd5b1
- Enrichment time
- 2026-09-01T13:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.