threat-intel Microsoft blames AI for delayed Exchange update, can’t say when it will arrive Microsoft is experiencing delays in deploying an Exchange update, attributing the issue to AI-related complexities. The delay has created a vulnerability, allowing attackers to exploit a zero-day flaw in on-prem SharePoint, potentially leading to unauthorized access and data compromise. This highlights a broader trend… The Register · Aug 17, 2026 High IRvulnerabilitycybersecurityexchange
threat-intel Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address This article details a vulnerability in Microsoft Exchange, dubbed "Ghost-Sender," that allows attackers to spoof any email address by exploiting misconfigurations in Exchange Online and on-premises hybrid environments u… Dark Reading · Jun 9, 2026 High email spoofingexchangephishing
threat-intel Microsoft Exchange Zero-Day Under Attack, No Patch Available A zero-day vulnerability (CVE-2026-42897) affecting Microsoft Exchange Outlook Web Access (OWA) is under active exploitation, allowing attackers to compromise mailboxes through cross-site scripting (XSS). Despite Microso… Dark Reading · May 18, 2026 High CVE-2026-42897BEzero-dayxssexchange
threat-intel ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More This week’s security news highlights several active exploits and attacks, including a widespread vulnerability in on-prem Exchange Servers, a Cisco SD-WAN controller compromise attributed to UAT-8616, and a significant s… The Hacker News · May 18, 2026 High CVE-2026-42897CVE-2026-20182CVE-2026-20127USexchangesupply chainnpm