Advertisement
APT28 Exploits Exchange OWA Zero-Day to Deploy OWAReaper Backdoor
Russian APT28 hackers exploit an Exchange OWA zero-day to deploy the OWAReaper backdoor, gaining persistent access to high-value government mailboxes.

CVE-2026-42897: Microsoft Exchange OWA XSS Zero-Day Under Attack
Active Zero-Day XSS vulnerability, CVE-2026-42897, impacts Microsoft Exchange OWA, allowing mailbox compromise. No patch available.
Pwn2Own Berlin: Microsoft Exchange, Windows 11 Zero-Day Exploits
Zero-day vulnerabilities in Microsoft Exchange, Windows 11, and Red Hat Enterprise Linux demonstrated at Pwn2Own Berlin. Runtime Rebel details the impact.
CVE-2024-49040: Microsoft Exchange Server Spoofing Vulnerability
Microsoft warns of CVE-2024-49040, a zero-day spoofing vulnerability in Exchange Server exploited to bypass security filters and impersonate trusted senders.

FamousSparrow Exploits Microsoft Exchange in Azerbaijani Energy Campaign
Bitdefender reveals a multi-wave intrusion by FamousSparrow targeting an Azerbaijani oil and gas firm via repeated Microsoft Exchange exploitation.
CVE-2024-21410: Protect Microsoft Exchange from NTLM Relay Attacks
Deep dive into CVE-2024-21410, a critical privilege escalation vulnerability in Microsoft Exchange. Learn how to detect exploits and implement EPA mitigations.