Max Severity Exchange Server Flaw Under Active Exploitation by Kremlin Hackers The latest revelations about Russian state hackers exploiting a maximum severity vulnerability in Microsoft Outlook's Exchange Server should send shockwaves through the cybersecurity community and beyond.
TA488, a group linked to the Kremlin, has been using this flaw to backdoor unpatched machines and steal sensitive information – including credentials – from unsuspecting victims.
TA488 is doubling down on "half click" exploits, where simply opening an email can trigger compromise.