Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Summary
Ars Technica reports that Kremlin-aligned TA488 is exploiting a max-severity Microsoft Exchange Server vulnerability (CVE-2026-42897) to backdoor unpatched networks via a half-click email exploit. The attack delivers a persistent browser-based implant named OWAReaper, enabling ongoing access and credential theft, with protections and indicators detailed by researchers and agencies.