Max-severity Exchange server flaw under active exploitation by Kremlin hackers
2026-08-01T08:51:33Z•3d410791f0ae0beeba82bd8a62472a07e11d98f4ff8073f1acbeb959f8bed705
2FA theftChinese threat actorsKremlin-linked actorsMicrosoft Entra IDMicrosoft Exchange ServerOAuthRoundcubeRussian threat actorsZimbraactive exploitationcredential theftdata theftemail compromiseespionageidentity reconnaissanceransomwarezero-day exploitation
What happened
Proofpoint RSS entries report active exploitation of a maximum-severity Microsoft Exchange Server vulnerability by Kremlin-linked actors, Russian exploitation of a Zimbra zero-day to steal email and two-factor authentication codes, suspected Chinese targeting of Roundcube mail servers, and techniques for validating stolen Microsoft Entra credentials and covertly collecting Entra user data. The feed also covers ransomware trends and recurring ransom payments, indicating significant threats to email, identity, and collaboration infrastructure.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- proofpoint_blog
- Record identifier
- 3d410791f0ae0beeba82bd8a62472a07e11d98f4ff8073f1acbeb959f8bed705
- Enrichment time
- 2026-08-01T08:51:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.