LIVE · cybersecurity feed
Live wire
patch

Microsoft working to fix Exchange Online mailbox quarantine issue

Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday. [...]

zeroday.news · 9d ago

Microsoft is actively working to resolve an issue within its Exchange Online service that has led to the incorrect quarantining of customer mailboxes since Sunday, July 19. The incident, identified by Microsoft as EX1436407, has resulted in affected users being unable to send or receive emails and experiencing difficulties accessing their calendars.

The company has attributed the problem to a recent infrastructure change. This change reportedly caused an unexpected increase in memory consumption due to indexing data, leading to an out-of-memory condition that subsequently triggered the erroneous mailbox quarantines. Microsoft has confirmed that users sending emails to these quarantined mailboxes may receive Non-delivery Reports (NDRs).

This current issue is a recurrence of a previous incident, tracked under the designation EX1434354, indicating that additional steps are required for a complete resolution. While Microsoft has not specified the geographical regions or the exact number of customers impacted, it has classified the event as an incident, which typically signifies a noticeable effect on users.

Remediation efforts involve an ongoing cleanup of the excessive indexing data. Progress on this cleanup was reported at 66% complete by Wednesday afternoon and had advanced to 72% by Wednesday evening. As memory levels are validated across different regions, mailboxes are gradually being removed from quarantine to expedite recovery.

Microsoft has not yet provided a definitive timeline for the full restoration of services but has indicated that an update with this information would be forthcoming. The next scheduled update on the incident was set for 6 p.m. UTC on the day of the report.

This is not the first time Exchange Online has faced issues involving email quarantines or incorrect spam flagging. In March 2025, an Exchange Online bug caused anti-spam systems to mistakenly quarantine emails. A similar issue occurred in May 2025, when a machine learning model incorrectly flagged emails from Gmail accounts as spam. More recently, in September, an anti-spam service problem blocked Exchange Online and Microsoft Teams users from opening URLs and also led to the mistaken quarantining of emails. In February, Microsoft addressed another Exchange Online issue where faulty heuristic detection rules, intended to block credential phishing, incorrectly flagged thousands of legitimate URLs as phishing links, leading to the quarantine of valid emails.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.