Russian hackers are actively exploiting a critical Exchange Server vulnerability that provides persistent access even after credential rotation.