Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
2026-06-09T20:51:47Z•151ed45452546cfacf178f75bb29a617f2e17b2d4face65b6f3c8086209a807d
CVE-2025-8088ai-wormscheck-point-vpn-zero-daycredential-theftemail-spoofingespionagemiasma-wormmicrosoft-exchangenpmpalo-alto-globalprotectphishingpyPIransomwaresupply-chainwinrar
What happened
A batch of high-impact DarkReading stories highlights multiple active exploit campaigns and supply-chain intrusions: a Microsoft Exchange 'Ghost‑Sender' spoofing technique affecting Exchange Online/hybrid setups; the Miasma supply‑chain worm compromising 73 Microsoft GitHub repositories; Russian actors weaponizing WinRAR (CVE-2025-8088) for cyberespionage against Ukraine; and a critical Check Point VPN zero-day under active exploitation (linked to Qilin ransomware). Also reported: an exploited Palo Alto PAN-OS/GlobalProtect auth‑bypass under active attack, expanding phishing and TDS campaigns(
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 151ed45452546cfacf178f75bb29a617f2e17b2d4face65b6f3c8086209a807d
- Enrichment time
- 2026-06-09T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.