Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

2026-07-30T01:23:22Z3b50ca7b026a6d4c3e0ca6ac964cf35427db65de84c2a4cc61135d0b2afd33fd
CVE-2026-20316AI securityArtifactoryCisco FMCDNS hijackingHugging Face breachLaundry BearMicrosoft ExchangeOWAReaperOutlook Web AccessRussian threat actorShinyHuntersVoid Blizzardactive exploitationbackdoorcredential exposurecritical infrastructurecybersecurity newshealthcare targetingoperational technologypre-authentication RCE|server BMCsstate-sponsored threat actorvBulletinwater utilitieszero-day exploitation

What happened

BleepingComputer security feed reporting multiple significant cybersecurity events, including Russian state-sponsored exploitation of an Exchange OWA zero-day to deploy the OWAReaper backdoor, active exploitation of Cisco Secure Firewall Management Center static credentials (CVE-2026-20316), attacks against healthcare and water-sector organizations, DNS hijacking, public exploitation of a critical vBulletin pre-authentication RCE, and widespread exposure of server BMC password hashes. The feed also covers AI-agent security risks and an AI-assisted breach involving exposed credentials and Artif

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
3b50ca7b026a6d4c3e0ca6ac964cf35427db65de84c2a4cc61135d0b2afd33fd
Enrichment time
2026-07-30T01:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Russian hackers exploit Exchange OWA zero-day for long-term mailbox access · Baitaphish