Home / Jul 31, 2026 / Story
0
#2 Ars Technica Security general July 30, 2026 at 20:57 UTC

Max-severity Exchange server flaw under active exploitation by Kremlin hackers

By Dan Goodin

AI Summary

Russian threat actors (Laundry Bear) are actively exploiting a max-severity flaw in Microsoft Outlook Web Access (OWA), active since July 22, 2026, targeting US and European government entities plus telecom, financial, hospitality, and aerospace sectors. The exploit is particularly dangerous because it survives credential rotation and full disk re-imaging, making remediation significantly more complex than standard incident response.

Relevance score: 91.0/100

# More from July 31