Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state-sponsored hackers are actively exploiting a maximum-severity vulnerability in Microsoft Exchange Server to gain persistent access to email accounts. The attack, dubbed OWAReaper, allows for unauthorized data theft and malware installation simply by opening a malicious email.
Why it matters
This exploit highlights the increasing sophistication of state-backed cyber warfare and the critical risks posed by 'half-click' vulnerabilities in enterprise communication software.
Beware: OWAReaper Max-severity Exchange server flaw under active exploitation by Kremlin hackers Exploits can give persistent server access that survives credential rotation and disk re-imaging.
34 Credit: Getty Images Credit: Getty Images Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in