Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

2026-07-30T14:51:40Z24916abb92b44c6f1fc4b2ef774cbeac33cff60d0fdd59260dcfa847581a9d2a
CVE-2026-20316CVE-2026-42897AI securityCISACisco Secure Firewall Management CenterLaundry BearMicrosoft ExchangeMicrosoft authenticationSBOMTA488Void Blizzardactive exploitationcritical infrastructurecross-site scriptingcyber espionageoperational technologyphishingspearphishingstatic credentialswater utilities

What happened

The feed reports active exploitation of two vulnerabilities: CVE-2026-42897, a Microsoft Exchange cross-site scripting flaw triggered when a malicious email is opened and attributed to the Russia-affiliated Laundry Bear/Void Blizzard group, and CVE-2026-20316, a Cisco Secure Firewall Management Center static-credentials flaw being exploited by attackers and flagged by CISA. It also covers phishing abusing Microsoft’s legitimate authentication workflow, a coordinated cyberattack against more than 30 Minnesota water utilities, updated CISA SBOM guidance, AI security tooling, and rising AI-driven

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
24916abb92b44c6f1fc4b2ef774cbeac33cff60d0fdd59260dcfa847581a9d2a
Enrichment time
2026-07-30T14:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) · Baitaphish