Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)
2026-07-30T14:51:40Z•24916abb92b44c6f1fc4b2ef774cbeac33cff60d0fdd59260dcfa847581a9d2a
CVE-2026-20316CVE-2026-42897AI securityCISACisco Secure Firewall Management CenterLaundry BearMicrosoft ExchangeMicrosoft authenticationSBOMTA488Void Blizzardactive exploitationcritical infrastructurecross-site scriptingcyber espionageoperational technologyphishingspearphishingstatic credentialswater utilities
What happened
The feed reports active exploitation of two vulnerabilities: CVE-2026-42897, a Microsoft Exchange cross-site scripting flaw triggered when a malicious email is opened and attributed to the Russia-affiliated Laundry Bear/Void Blizzard group, and CVE-2026-20316, a Cisco Secure Firewall Management Center static-credentials flaw being exploited by attackers and flagged by CISA. It also covers phishing abusing Microsoft’s legitimate authentication workflow, a coordinated cyberattack against more than 30 Minnesota water utilities, updated CISA SBOM guidance, AI security tooling, and rising AI-driven
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 24916abb92b44c6f1fc4b2ef774cbeac33cff60d0fdd59260dcfa847581a9d2a
- Enrichment time
- 2026-07-30T14:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.