Max-severity Exchange server flaw under active exploitation by Kremlin hackers

2026-08-01T08:51:33Z3d410791f0ae0beeba82bd8a62472a07e11d98f4ff8073f1acbeb959f8bed705
2FA theftChinese threat actorsKremlin-linked actorsMicrosoft Entra IDMicrosoft Exchange ServerOAuthRoundcubeRussian threat actorsZimbraactive exploitationcredential theftdata theftemail compromiseespionageidentity reconnaissanceransomwarezero-day exploitation

What happened

Proofpoint RSS entries report active exploitation of a maximum-severity Microsoft Exchange Server vulnerability by Kremlin-linked actors, Russian exploitation of a Zimbra zero-day to steal email and two-factor authentication codes, suspected Chinese targeting of Roundcube mail servers, and techniques for validating stolen Microsoft Entra credentials and covertly collecting Entra user data. The feed also covers ransomware trends and recurring ransom payments, indicating significant threats to email, identity, and collaboration infrastructure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
proofpoint_blog
Record identifier
3d410791f0ae0beeba82bd8a62472a07e11d98f4ff8073f1acbeb959f8bed705
Enrichment time
2026-08-01T08:51:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.