Max-severity Exchange server flaw under active exploitation by Kremlin hackers

Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday.
Reported by 1 outlet — Ars Technica. See all sources ↓
Russian state hackers are actively using a serious flaw in Microsoft Exchange Server to attack computers. The flaw is rated maximum severity and lets attackers install backdoors and steal passwords. The hackers belong to a group called TA488, also known as Laundry Bear or Void Blizzard, which works for the Kremlin. Security researchers from Proofpoint and the NSA warned about these attacks last week.
Why it matters
If your organization uses Exchange Server and hasn't patched the flaw, hackers could read your emails and steal sensitive data. This shows how important it is to keep software updated to protect against state‑sponsored cyber threats.
- What is the name of the hacker group exploiting the Exchange flaw?
- The group is called TA488, also tracked as Laundry Bear or Void Blizzard.
- Who warned about the attacks?
- Proofpoint researchers and the National Security Agency jointly warned about the activity.
How outlets are framing the same story
Here's how each outlet is covering the story — compare their headlines and timing at a glance.
All outlets present the story with the same focus on the Russian hacking group exploiting the Exchange flaw.
- Coverage card1 outlet1CoverageScouting report
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Sources1TypeCoverageArs Technica