Microsoft Exchange is a core email and calendaring platform (on-premises Exchange Server and cloud-based Exchange Online as part of Microsoft 365) that underpins enterprise communications and identity workflows.
Overview
Microsoft Exchange is a core email and calendaring platform (on-premises Exchange Server and cloud-based Exchange Online as part of Microsoft 365) that underpins enterprise communications and identity workflows. In cybersecurity, it is a high-value target for credential access, data exfiltration, and abuse of email-related data such as archives and tokens. Its security posture is a recurring focus of advisories, ecosystem changes, and security models like Zero Trust.
Related Threat Clusters
-
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Since July 2025, Russian state-backed hackers, known as Laundry Bear, have exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite to infiltrate Western government and commercial…
82 articles · Updated July 23, 2026 -
Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems
A financially motivated threat actor, Storm-1175, previously linked to Medusa ransomware, has begun deploying a new ransomware strain named StormEncryptor. This campaign was initiated after exploiting an…
11 articles · Updated August 10, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
10 articles · Updated May 13, 2026 -
Iranian Cyberespionage Targets Iraqi Government Officials
In 2024, Iranian APT group BladedFeline launched a cyber campaign against Kurdish and Iraqi government officials, utilizing advanced malware tools including the Shahmaran backdoor and the Whisper backdoor. The attacks…
2 articles · Updated May 13, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Italy Extradites Chinese Hacker Xu Zewei to the U.S. for COVID-19 Research Theft
Xu Zewei, a 33-year-old Chinese national, was extradited from Italy to the United States on April 27, 2026, following his arrest in Milan on July 3, 2025. He is accused of participating in cyberattacks directed by the…
51 articles · Updated April 26, 2026 -
Ivanti Sentry Vulnerabilities Allow Remote Code Execution and Admin Access
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root…
38 articles · Updated June 10, 2026 -
Chinese APT FamousSparrow Breaches Energy Sector via Microsoft Exchange Exploit
Chinese state-aligned hackers, identified as FamousSparrow, infiltrated an Azerbaijani oil and gas company by exploiting an unpatched Microsoft Exchange server. The attack, which occurred from late December 2025 to late…
2 articles · Updated May 14, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
281 articles · Updated April 2, 2026
Recent Intelligence Reports
- New StormEncryptor ransomware used by former Medusa affiliate — Bleepingcomputer · August 10, 2026
- New StormEncryptor ransomware used by former Medusa affiliate — Bleepingcomputer · August 10, 2026
- C80gl8yvj9go — www.bbc.com · August 8, 2026
- Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover — Csoonline · July 30, 2026
- Russian hackers use OWAReaper to keep Microsoft OWA access after resets — Feeds.4Sysops · July 30, 2026
- 826029 — www.cybersecuritydive.com · July 25, 2026
- Russian APT Laundry Bear perfects zero — Computerweekly · July 24, 2026
- Russian hackers can steal government emails without victims clicking a link, cyber agencies warn — www.nextgov.com · July 24, 2026