Skip to main content

Exchange Exploit, Dropbox Breach, & Cloud Phishing Campaigns

5 min read Runtime Rebel Intel
Primary source: securityweek.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Attackers are exploiting Microsoft Exchange, compromising Dropbox accounts, and targeting cloud users via phishing campaigns.
  • Affected systems include unpatched Microsoft Exchange Servers, Dropbox accounts, Microsoft 365, and Google Workspace users.
  • Defenders must patch Exchange, secure cloud accounts, and implement strong MFA with comprehensive phishing awareness.

Advertisement

This week’s cybersecurity intelligence report from Runtime Rebel, based on a recent SecurityWeek roundup, uncovers several pressing threats demanding immediate attention from security professionals. The landscape features a publicly available exploit for a high-severity Microsoft Exchange Server vulnerability, confirmed Dropbox account compromises, and active phishing campaigns targeting cloud service credentials. These incidents underscore the critical need for proactive patching, vigilant user education, and enhanced security controls across enterprise environments, as detailed by SecurityWeek.

Key Threat Intelligence Highlights

CVE-2026-62911 Exploit for Microsoft Exchange Demands Immediate Action

One of the most concerning developments is the publication of exploit code for CVE-2026-62911, a high-severity vulnerability impacting Microsoft Exchange Server. This flaw, originally patched in August, has become a significant risk due to observed widespread negligence in applying updates. The Netherlands National Cyber Security Centre has issued a warning, and The Shadowserver Foundation reported on September 1st that over 21,000 Exchange servers remained unpatched. The availability of exploit code significantly lowers the barrier for attackers, making securing unpatched Exchange servers an urgent priority for any organization still vulnerable. Organizations must act swiftly to prevent potential compromise from this widely exposed vulnerability. Security teams should thoroughly investigate how to detect CVE-2026-62911 exploit attempts and apply patches without delay.

Dropbox Account Compromises via Lenovo Login Integration

Dropbox has notified approximately 5,000 users regarding compromised accounts resulting from an issue with Lenovo’s email verification process. Attackers registered Lenovo IDs using victims’ email addresses, then exploited this to gain access to their Dropbox accounts. While Dropbox has closed all unauthorized sessions and access, this incident highlights the risks associated with third-party login integrations and identity federation. Users should review their account activity and ensure multi-factor authentication (MFA) is enabled for all critical services.

Knight Office AitM Phishing Targets Cloud Credentials

A newly identified adversary-in-the-middle (AitM) phishing kit, dubbed ‘Knight Office’, is actively targeting users of Microsoft 365 and Google Workspace to steal account credentials. Huntress reports that this kit employs token theft, a sophisticated technique that grants attackers an already-authenticated session, effectively bypassing traditional password requirements and MFA mechanisms. This bypass capability makes mitigation for Knight Office phishing challenging and requires advanced detection capabilities and user awareness regarding phishing tactics. Organizations should educate users about the evolving nature of phishing, including AitM attacks, and implement Conditional Access policies to scrutinize session tokens.

Coder’s Module Registry Served Malware

In a supply chain-style attack, a threat actor compromised Coder’s Cloudflare infrastructure, injecting unauthorized IP addresses that delivered malicious code. This code, a credential stealer, was served through Coder’s module registry website to a subset of users for a brief period. This incident underscores the ongoing threat of software supply chain attacks and the critical importance of validating code sources and implementing comprehensive endpoint detection and response (EDR) solutions.

Microsoft Cloud Patches and Proactive Defenses

Microsoft has released server-side patches for nine vulnerabilities across various cloud services, including Entra ID, Azure Cosmos DB, Power Automate, and Copilot Studio. These fixes require no direct action from customers, demonstrating Microsoft’s continuous efforts to secure its cloud infrastructure. While these specific fixes are transparent to users, the frequent nature of such patches highlights the importance of keeping all linked on-premises systems updated.

Cybersecurity for Water Utilities in Texas

In a significant federal-private sector initiative, the White House and the Governor of Texas launched Project Watershed 250. This program aims to provide water and wastewater utilities across Texas with free cyber defense resources, enhancing their resilience against cyberattacks from sophisticated foreign adversaries, including China and Iran. This proactive measure recognizes the critical infrastructure sector’s vulnerability to nation-state threats.

Actionable Recommendations and Mitigations

To effectively counter these diverse threats, security professionals should prioritize the following actions:

  • Patch Immediately: Apply the August patch for CVE-2026-62911 on all Microsoft Exchange Servers. Regularly scan for and remediate unpatched systems to prevent exploitation.
  • Strengthen Authentication: Implement and enforce multi-factor authentication (MFA) across all cloud services, including Dropbox, Microsoft 365, and Google Workspace. Educate users on the risks of token theft and sophisticated phishing techniques.
  • Monitor Account Activity: Regularly review logs for unusual login attempts, account activity, and unauthorized changes, especially for cloud storage and productivity suites.
  • Enhance Phishing Awareness: Conduct frequent training on identifying advanced phishing and AitM attacks. Advise users to be wary of suspicious login prompts, even if they appear legitimate.
  • Supply Chain Security: For software development and deployment, implement strict controls for code integrity and source validation, particularly when consuming third-party modules or libraries. Utilize security solutions that can detect injected malicious code.
  • Endpoint Protection: Deploy and maintain advanced endpoint detection and response (EDR) solutions to identify and neutralize credential stealers and other malware delivered through supply chain compromises.

Related: Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage, ToxicPanda 2.0 Android Malware Abuses Wireless ADB and VPN

Advertisement

Advertisement