Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

2026-07-30T13:23:22Za52daa82dcc05f409576030e7b13a93bae693371f8d9852cc2f1b0fe5d7f1c32
CVE-2026-20316AI securityBMCCISA guidanceCisco FMCDNS hijackingExchange OWALaundry BearOT securityOWAReaperRussian state-sponsoredShinyHuntersVoid Blizzardactive exploitationcritical infrastructureexposed credentialshealthcarepassword hash leakagepre-auth RCEsupply-chain compromisevBulletinwater utilitieszero-day

What happened

The feed reports multiple significant cybersecurity events, including alleged Russian state-sponsored exploitation of an Exchange OWA zero-day for persistent mailbox access, active exploitation of Cisco Secure Firewall Management Center static credentials (CVE-2026-20316), attacks against healthcare and water-sector organizations, supply-chain and DNS hijacking incidents, AI-agent credential misuse, and critical publicly exploited vulnerabilities in vBulletin and server BMC interfaces. The most urgent items involve active exploitation, critical infrastructure targeting, and unauthenticated orب

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
a52daa82dcc05f409576030e7b13a93bae693371f8d9852cc2f1b0fe5d7f1c32
Enrichment time
2026-07-30T13:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.