Microsoft details CVE-2026-73570: unauthenticated command injection hitting mail servers
yuridiogenes · x · 2026-10-01
Microsoft Threat Intelligence detailed exploitation of CVE-2026-73570, an unauthenticated OS command injection in internet-facing mail servers exploitable without authentication or user interaction.
Successful exploitation enabled webshell deployment, reverse shells, privilege escalation, persistent remote-access tooling, and theft of credentials and mailbox data, with both automated payload delivery and hands-on-keyboard activity observed.
Analysis of confirmed compromises revealed multiple attack paths and pre-disclosure reconnaissance targeting the same injection path before public disclosure. The full research covers technical details, detection opportunities, and mitigation guidance.
More from Safety
- NYT: Can the AI Arms Race Stop Short of Disaster? Lessons from Cold War Arms Control — soumitrashukla9 · 2026-10-01
- Security Researcher: Labs Are Weaponizing Cyber Narratives to Frighten Non-Experts — basedjensen · 2026-10-01
- LessWrong essay argues against strong decision-theoretic realism, highlighting ASI path dependence — dfrsrchtwts · 2026-10-01
- AI coding agents write insecure Supabase RLS policies — dev's CLI scan finds 12 high-severity issues — Real_KingZeotic · 2026-10-01
- Tracking Singularity logs agent incidents: 950 Claude agents find novel enzyme system, OpenAI agents hacked Hugging Face — dejavucoder · 2026-10-01
- Many headline AI 'incidents' are really policy failures, argues researcher — austinc3301 · 2026-10-01