CVE-2021-26858
published 2021-03-03CVE-2021-26858: Microsoft Exchange Server Remote Code Execution Vulnerability
PriorityP190high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
89.51%
99.8th percentile
Microsoft Exchange Server Remote Code Execution Vulnerability
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | exchange_server | — | — |
| microsoft | microsoft_exchange_server_2013_cumulative_update_21 | >= 15.00.0 < publication | publication |
| microsoft | microsoft_exchange_server_2013_cumulative_update_22 | >= 15.00.0 < publication | publication |
| microsoft | microsoft_exchange_server_2013_cumulative_update_23 | >= 15.00.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_10 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_11 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_12 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_13 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_14 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_15 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_16 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_17 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_18 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_19 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_8 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2016_cumulative_update_9 | >= 15.01.0 < publication | publication |
| microsoft | microsoft_exchange_server_2019 | >= 15.02.0 < publication | publication |
| microsoft | microsoft_exchange_server_2019_cumulative_update_1 | >= 15.02.0 < publication | publication |
| microsoft | microsoft_exchange_server_2019_cumulative_update_2 | >= 15.02.0 < publication | publication |
| microsoft | microsoft_exchange_server_2019_cumulative_update_3 | >= 15.02.0 < publication | publication |
| microsoft | microsoft_exchange_server_2019_cumulative_update_4 | >= 15.02.0 < publication | publication |
| microsoft | microsoft_exchange_server_2019_cumulative_update_5 | >= 15.02.0 < publication | publication |
Detection & IOCsextracted from sources · hover to see the quote
- →Hunt for anomalous .aspx webshell files in Exchange Server directories: \inetpub\wwwroot\aspnet_client\, \inetpub\wwwroot\aspnet_client\system_web\, and \FrontEnd\HttpProxy\owa\auth\ ↗
- →Alert on and block connections to PlugX C2 IPs 91.220.203.86 and 91.220.203.197, especially from hosts running Microsoft Exchange services ↗
- →Detect DLL search-order hijacking post-exploitation: look for SRVCON.OCX (PlugX Loader) and rapi.dll (Whitebird Loader) loaded by legitimate executables ↗
- →Use Tenable plugin ID 147193 to scan Exchange Server directories for anomalous .aspx files as IOCs for Hafnium/ProxyLogon webshell implantation ↗
- →Detect Lemon Duck WMIC-based AV removal activity: wmic.exe commands uninstalling ESET, Kaspersky, stopping wuauserv and Windows Defender post-Exchange compromise ↗
- →Detect post-exploitation tools Nishang and PowerCat running on Exchange servers as indicators of HAFNIUM/ProxyLogon compromise ↗
- ·Patching Exchange Servers does NOT remove already-implanted webshells; IOC scanning for webshells must be performed even after patches are applied ↗
- ·Microsoft Exchange Server 2010 may also be vulnerable but is NOT covered by the four CVE patches issued March 2, 2021; separate defense-in-depth guidance applies ↗
- ·Restricting untrusted connections to port 443 only mitigates the initial CVE-2021-26855 step; other parts of the exploit chain (including CVE-2021-26858) can still be triggered if attackers already have access or trick an admin into running a malicious file ↗
- ·Webshells left behind by initial threat actors (e.g., HAFNIUM/Calypso) can be piggybacked by other threat actors scanning for them; removal is critical to prevent secondary compromise ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rwm8-8c4x-v87q: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-2685
ghsa_unreviewed·2022-05-24·CVSS 9.1
CVE-2021-27065 [CRITICAL] CWE-22 GHSA-rwm8-8c4x-v87q: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-2685
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27078.
GHSA
GHSA-6784-2mh5-cq56: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-2685
ghsa_unreviewed·2022-05-24·CVSS 9.1
CVE-2021-26855 [CRITICAL] CWE-918 GHSA-6784-2mh5-cq56: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-2685
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
GHSA
GHSA-2xf7-r7hp-r5qc: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26855, CVE-2021-26857, CVE-2021-2685
ghsa_unreviewed·2022-05-24·CVSS 9.1
CVE-2021-26854 [CRITICAL] GHSA-2xf7-r7hp-r5qc: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26855, CVE-2021-26857, CVE-2021-2685
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
GHSA
GHSA-r4wp-245q-vr5w: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-2685
ghsa_unreviewed·2022-05-24·CVSS 9.1
CVE-2021-26858 [CRITICAL] GHSA-r4wp-245q-vr5w: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-2685
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-27065, CVE-2021-27078.
GHSA
Rails is bad
ghsa_unreviewed·2022-05-24·CVSS 9.1
CVE-2021-26857 [CRITICAL] CWE-502 Rails is bad
Rails is bad
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
GHSA
GHSA-xc64-jf3q-gg7j: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-2685
ghsa_unreviewed·2022-05-24·CVSS 6.6
CVE-2021-26412 [MEDIUM] GHSA-xc64-jf3q-gg7j: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-2685
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, CVE-2021-27078.
GHSA
GHSA-5rg7-hgww-7chr: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-2685
ghsa_unreviewed·2022-05-24·CVSS 9.1
CVE-2021-27078 [CRITICAL] GHSA-5rg7-hgww-7chr: Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-2685
Microsoft Exchange Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065.
Project0
The More You Know, The More You Know You Don’t Know - Project Zero
project_zero·2022-04-01
CVE-2016-4654 The More You Know, The More You Know You Don’t Know - Project Zero
A Year in Review of 0-days Used In-the-Wild in 2021
Posted by Maddie Stone, Google Project Zero
This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019]. Each year we’ve looked back at all of the detected and disclosed in-the-wild 0-days as a group and synthesized what we think the trends and takeaways are. The goal of this report is not to detail each individual exploit, but instead to analyze the exploits from the year as a group, looking for trends, gaps, lessons learned, successes, etc. If you’re interested in the analysis of individual exploits, please check out our root cause analysis repository.
We perform and share this analysis in order to make 0-day hard. We want it to be more costly, more resource intensive, and overall more difficult for
VulnCheck
Microsoft Exchange Server Remote Code Execution Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-26858 [HIGH] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Affected: Microsoft Exchange Server
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://cisa.gov/news-events/alerts/2021/03/02/microsoft-releases-out-band-security-updates-exchange-server; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers; https://us-cert.cisa.gov/ncas/alerts/aa21-062a; https://www.crowdstrike.com/blog/falcon-complete-stops-microsoft-exchange-server-z
Project0
Project Zero RCA: CVE-2021-26855: Microsoft Exchange Server-Side Request Forgery
project_zero·CVSS 9.1
CVE-2021-26855 [CRITICAL] Project Zero RCA: CVE-2021-26855: Microsoft Exchange Server-Side Request Forgery
# CVE-2021-26855: Microsoft Exchange Server-Side Request Forgery
*Anthony Weems, Michael Weber, Dallas Kaman*
## The Basics
**Disclosure or Patch Date:** March 2 2021
**Product:** Microsoft Microsoft Exchange Server
**Advisory:** https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855
**Affected Versions:** [Exchange 2010, 2013, 2016, and 2019](https://techcommunity.microsoft.com/t5/exchange-team-blog/march-2021-exchange-server-security-updates-for-older-cumulative/ba-p/2192020) before KB5000871.
**First Patched Version:** [KB5000871](https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-2016-and-2013-march-2-2021-kb5000871-9800a6bb-0a21-4ee7-b9da-fa85b3e1d23b)
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-
CISA
Microsoft Exchange Server Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2021-26858 [HIGH] Microsoft Exchange Server Remote Code Execution Vulnerability
Vulnerability: Microsoft Exchange Server Remote Code Execution Vulnerability
Affected: Microsoft Exchange Server
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Required Action: Apply updates per vendor instructions.
Notes: Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26858
Remediation Due Date: 2022-05-03
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-26857 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 9.1
CVE-2021-26855 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-27065 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Microsoft
Microsoft Exchange Server Remote Code Execution Vulnerability
vendor_msrc·2021-03-09·CVSS 7.8
CVE-2021-26858 [CRITICAL] Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
FAQ: Is this vulnerability being used in an active attack?
Yes. The vulnerability described in this CVE is one of four vulnerabilities that are being exploited in an active attack. The security updates address this attack. More information can be found here: https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server.
What is the target for this attack?
The initial attack in this attack chain targets an Exchange On-prem server that is able to receive untrusted connections from an external source. In addition, the Exchange server would need to be running Microsoft Exchange Server 2013, 2016, or 2019.
Where can I get more information about how to protect myself from the vulnerabilities?
Pleas
Nuclei
Microsoft Exchange Server SSRF Vulnerability
nuclei·CVSS 7.2
CVE-2021-26855 [HIGH] Microsoft Exchange Server SSRF Vulnerability
Microsoft Exchange Server SSRF Vulnerability
This vulnerability is part of an attack chain that could allow remote code execution on Microsoft Exchange Server. The initial attack requires the ability to make an untrusted connection to Exchange server port 443. Other portions of the chain can be triggered if an attacker already has access or can convince an administrator to open a malicious file. Be aware his CVE ID is unique from CVE-2021-26412, CVE-2021-26854, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065, and CVE-2021-27078.
Template:
id: CVE-2021-26855
info:
name: Microsoft Exchange Server SSRF Vulnerability
author: madrobot
severity: critical
description: This vulnerability is part of an attack chain that could allow remote code execution on Microsoft Exchange Server. The initial
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Recorded Future
2025 Cloud Threat Hunting and Defense Landscape
blogs_recorded_future·2026-02-19
2025 Cloud Threat Hunting and Defense Landscape
## 2025 Cloud Threat Hunting and Defense Landscape
## Executive Summary
Insikt Group has observed continued trends of growth and increased activity of threat actors leveraging and exploiting cloud infrastructure to broaden the number of victims they target and infect. Recent reporting across the observed incidents shows that cloud-focused threats are converging on a few consistent patterns, which serve as the main sections of this report:
Exploitation and Misconfiguration
Cloud Abuse
Cloud Ransomware
Credential Abuse, Account Takeover, and Unauthorized Access
Third-Party Compromise
Across cases, initial access frequently comes from vulnerable or misconfigured services exposed to the internet — including application delivery controllers, monitoring dashboards, email security gateway
Huntress
Ten Years of Resilience, Innovation & Community-Driven Defense
blogs_huntress·2025-08-25·CVSS 8.8
[HIGH] Ten Years of Resilience, Innovation & Community-Driven Defense
The world of cybersecurity has been a wild ride over the last decade. As attackers stepped up their game year over year, the security community responded and adapted with resilience and ingenuity to each new wave of threats.
Attackers tested our limits time and time again with bolder, more cutting-edge cyberattacks: ransomware, supply chain compromises, zero-day vulnerabilities, and more. But every single breach, compromise, and exploited vulnerability taught us something new, pushed us harder to innovate and stay steps ahead, brought our security community closer together, and rallied us to wreck hackers.
As we celebrate our 10th anniversary at Huntress this month, we’re pausing to look back at the events that have shaped the entire cybersecurity community. Understanding where we've bee
Bleepingcomputer
US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks
blogs_bleepingcomputer·2025-05-02·CVSS 10.0
[CRITICAL] US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks
## US indicts Black Kingdom ransomware admin for Microsoft Exchange attacks
## Bill Toulas
"When the malware was successful, the ransomware then created a ransom note on the victim's system that directed the victim to send $10,000 worth of Bitcoin to a cryptocurrency address controlled by a co-conspirator and to send proof of this payment to a Black Kingdom email address," reads another part of the announcement.
The U.S. DoJ highlights that Ahmed designed Black Kingdom ransomware to exploit a vulnerability in Microsoft Exchange for initial access to targeted computers.
This was first reported in March 2021 by researcher Marcus Hutchins , who discovered web shells deployed by Black Kingdom ransomware operators on Exchange servers vulnerable to ProxyLogon attacks.
The ProxyLogon flaw re
Tenable
Salt Typhoon: An Analysis of Vulnerabilities Exploited by this State-Sponsored Actor
blogs_tenable·2025-01-23
Salt Typhoon: An Analysis of Vulnerabilities Exploited by this State-Sponsored Actor
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
blogs_trendmicro·2024-11-25
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
APT & Targeted Attacks
## Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
Since 2023, APT group Earth Estries has aggressively targeted key industries globally with sophisticated techniques and new backdoors, like GHOSTSPIDER and MASOL RAT, for prolonged espionage operations.
By: Leon M Chang, Theo Chen, Lenart Bermejo, Ted Lee Nov 25, 2024 Read time: ( words)
Save to Folio
## Summary
Earth Estries, a Chinese APT group, has primarily targeted critical sectors like telecommunications and government entities across the US, Asia-Pacific, Middle East, and South Africa since 2023.
The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian telecommunications companies and governm
Trendmicro
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
blogs_trendmicro·2024-11-25
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
APT y ataques dirigidos
## Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
Since 2023, APT group Earth Estries has aggressively targeted key industries globally with sophisticated techniques and new backdoors, like GHOSTSPIDER and MASOL RAT, for prolonged espionage operations.
By: Leon M Chang, Theo Chen, Lenart Bermejo, Ted Lee Nov 25, 2024 Read time: ( words)
Save to Folio
## Summary
Earth Estries, a Chinese APT group, has primarily targeted critical sectors like telecommunications and government entities across the US, Asia-Pacific, Middle East, and South Africa since 2023.
The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian telecommunications companies and govern
Bleepingcomputer
Salt Typhoon hackers backdoor telcos with new GhostSpider malware
blogs_bleepingcomputer·2024-11-25
Salt Typhoon hackers backdoor telcos with new GhostSpider malware
## Salt Typhoon hackers backdoor telcos with new GhostSpider malware
## Bill Toulas
The Chinese state-sponsored hacking group Salt Typhoon has been observed utilizing a new "GhostSpider" backdoor in attacks against telecommunication service providers.
The backdoor was discovered by Trend Micro, which has been monitoring Salt Typhoon's attacks against critical infrastructure and government organizations worldwide.
Along with GhostSpider, Trend Micro discovered that the threat group also uses a previously documented Linux backdoor named 'Masol RAT,' a rootkit named 'Demodex,' and a modular backdoor shared among Chinese APT groups named 'SnappyBee.'
## Salt Typhoon's global campaigns
Salt Typhoon (aka 'Earth Estries', 'GhostEmperor', or 'UNC2286') is a sophisticated hacking group that h
Trendmicro
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
blogs_trendmicro·2024-11-25
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
APT & Targeted Attacks
## Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
Since 2023, APT group Earth Estries has aggressively targeted key industries globally with sophisticated techniques and new backdoors, like GHOSTSPIDER and MASOL RAT, for prolonged espionage operations.
By: Leon M Chang, Theo Chen, Lenart Bermejo, Ted Lee 2024/11/25 Read time: ( words)
Save to Folio
## Summary
Earth Estries, a Chinese APT group, has primarily targeted critical sectors like telecommunications and government entities across the US, Asia-Pacific, Middle East, and South Africa since 2023.
The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian telecommunications companies and governmen
Trendmicro
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
blogs_trendmicro·2024-11-25
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
APT & Targeted Attacks
# Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
Since 2023, APT group Earth Estries has aggressively targeted key industries globally with sophisticated techniques and new backdoors, like GHOSTSPIDER and MASOL RAT, for prolonged espionage operations.
By: Leon M Chang, Theo Chen, Lenart Bermejo, Ted Lee
2024/11/25
Read time: ( words)
Save to Folio
#### Summary
- Earth Estries, a Chinese APT group, has primarily targeted critical sectors like telecommunications and government entities across the US, Asia-Pacific, Middle East, and South Africa since 2023.
- The group employs advanced attack techniques and multiple backdoors, such as GHOSTSPIDER, SNAPPYBEE, and MASOL RAT, affecting several Southeast Asian telecommunications companies and gove
Trendmicro
Unmasking Prometei A Deep Dive Into Our MXDR Findings
blogs_trendmicro·2024-10-23·CVSS 9.8
[CRITICAL] Unmasking Prometei A Deep Dive Into Our MXDR Findings
Cyber Threats
# Unmasking Prometei: A Deep Dive Into Our MXDR Findings
How does Prometei insidiously operate in a compromised system? This Managed Extended Detection and Response investigation conducted with the help of Trend Vision One provides a comprehensive analysis of the inner workings of this botnet so users can stop the threat in its tracks before it inflicts damage to the system.
By: Buddy Tancio, Bren Matthew Ebriega, Mohamed Fahmy
2024/10/23
Read time: ( words)
Save to Folio
Key Takeaways
- The botnet Prometei was used in an attempt to infiltrate a customer’s system through what appeared to be a targeted brute force attack.
- Our Managed Extended Detection and Response investigation leveraged Trend Vision One and its response actions to detect and mitigate the attack proa
Bleepingcomputer
AT&T, Verizon reportedly hacked to target US govt wiretapping platform
blogs_bleepingcomputer·2024-10-07
AT&T, Verizon reportedly hacked to target US govt wiretapping platform
## AT&T, Verizon reportedly hacked to target US govt wiretapping platform
## Ionut Ilascu
Multiple U.S. broadband providers, including Verizon, AT&T, and Lumen Technologies, have been breached by a Chinese hacking group tracked as Salt Typhoon, the Wall Street Journal reports.
The purpose of the attack appears to be intelligence collection as the hackers might have had access to systems used by the U.S. federal government for court-authorized network wiretapping requests.
It is unclear when the intrusion occurred, but WSJ cites people familiar with the matter, saying that "for months or longer, the hackers might have held access to network infrastructure used to cooperate with lawful U.S. requests for communications data."
Salt Typhoon is the name that Microsoft gave to this particula
Securelist
From Caribbean shores to your devices: analyzing Cuba ransomware
blogs_securelist·2023-09-11
From Caribbean shores to your devices: analyzing Cuba ransomware
Table of Contents
Introduction
Cuba ransomware gang
Victimology
Ransomware
Cuba extortion model
Arsenal
Profits
Investigation of a Cuba-related incident and analysis of the malware
Host: SRV_STORAGE
Bughatch
SRV_Service host
Veeamp
Avast Anti-Rootkit driver
Burntcigar
SRV_MAIL host (Exchange server)
SqlDbAdmin
Cobalt Strike
New malware
BYOVD (Bring Your Own Vulnerable Driver)
Conclusion
Appendix
Authors
Alexander Kirichenko
Gleb Ivanov
## Introduction
Knowledge is our best weapon in the fight against cybercrime. An understanding of how various gangs operate and what tools they use helps build competent defenses and investigate incidents. This report takes a close look at the history of the Cuba group, and their attack tactics, techniques and procedures. We hope th
Securelist
Analysis of Cuba ransomware gang activity and tooling
blogs_securelist·2023-09-11
Analysis of Cuba ransomware gang activity and tooling
Table of Contents
- Introduction
- Cuba ransomware gang
- Victimology
- Ransomware
- Cuba extortion model
- Arsenal
- Profits
- Investigation of a Cuba-related incident and analysis of the malware
- New malware
- BYOVD (Bring Your Own Vulnerable Driver)
- Conclusion
- Appendix
Authors
- Alexander Kirichenko
- Gleb Ivanov
## Introduction
Knowledge is our best weapon in the fight against cybercrime. An understanding of how various gangs operate and what tools they use helps build competent defenses and investigate incidents. This report takes a close look at the history of the Cuba group, and their attack tactics, techniques and procedures. We hope this article will help you to stay one step ahead of threats like this one.
## Cuba ransomware gang
Cuba data leak site
The group’s offe
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
ProxyNotShell, OWASSRF, TabShell: Patch Your Microsoft Exchange Servers Now
blogs_tenable·2023-01-31
ProxyNotShell, OWASSRF, TabShell: Patch Your Microsoft Exchange Servers Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Cuba unter der Lupe
blogs_trendmicro·2023-01-18
Cuba unter der Lupe
Ransomware
## Cuba unter der Lupe
Die Cuba-Ransomware gilt mit einer umfangreichen Infrastruktur, beeindruckenden Tools und zugehöriger Malware als wichtiger Akteur und wird dies durch kontinuierliche Weiterentwicklung auch bleiben. Gute Kenntnisse dazu führen zu einem höheren Schutz davor.
By: Trend Micro Jan 18, 2023 Read time: ( words)
Save to Folio
Cuba Ransomware geriet gegen Ende 2021 mit einer Reihe hochkarätiger Angriffe, unter anderem auf europäische Regierungsbehörden, in die Schlagzeilen. Bis August 2022 kompromittierten die Akteure weltweit über 100 Einrichtungen, forderten über 145 Mio. Dollar und erhielten über 60 Mio. Dollar an Lösegeldzahlungen, wie aus einem gemeinsamen Bericht des FBI und der CISA vom Dezember 2022 hervorgeht. Wie viele moderne Ransomware-Betreiber n
Trendmicro
BlackCat Ransomware unter der Lupe
blogs_trendmicro·2022-11-17
BlackCat Ransomware unter der Lupe
Ransomware
## BlackCat Ransomware unter der Lupe
BlackCat Ransomware ist für seine unkonventionellen Methoden und fortschrittlichen Erpressungstechniken bekannt. Wir haben die Aktivitäten der RaaS-Gruppe untersucht und zeigen, wie Unternehmen ihren Schutz vor dieser Ransomware verbessern können.
By: Trend Micro Nov 17, 2022 Read time: ( words)
Save to Folio
BlackCat (auch bekannt als AlphaVM, AlphaV oder ALPHV) wurde erstmals Mitte November 2021 von Forschern des MalwareHunterTeams entdeckt und erlangte schnell Aufmerksamkeit, da es sich um die erste große professionelle Ransomware-Familie handelte, die in Rust geschrieben wurde. Dies ist eine plattformübergreifende Sprache , die es ermöglicht, Malware einfach an verschiedene Betriebssysteme wie Windows und Linux anzupassen.
Die Grup
Qualys
NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
blogs_qualys·2022-10-07·CVSS 10.0
[CRITICAL] NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
## Table of Contents
Detect & Prioritize 20 Publicly Known Vulnerabilities using VMDR 2.0
Identify Vulnerable Assets using Qualys Threat Protection
Recommendations & Mitigations
Contributors
On October 6, 2022, the United States National Security Agency (NSA) released a cybersecurity advisory on the Chinese government—officially known as the People’s Republic of China (PRC) states-sponsored cyber actors’ activity to seek national interests. These malicious cyber activities attributed to the Chinese government targeted, and persist to target, a mixture of industries and organizations in the United States. They provide the top CVEs used since 2020 by the People’s Republic of China (PRC) states-sponsored cyber actors as evaluated by the National Security Agency (NSA), Cybersecurity and I
Qualys
NSA Alert: Topmost CVEs Actively Exploited By PRC Sponsored Cyber Actors | Qualys
blogs_qualys·2022-10-07
NSA Alert: Topmost CVEs Actively Exploited By PRC Sponsored Cyber Actors | Qualys
#### Table of Contents
- Detect & Prioritize 20 Publicly Known Vulnerabilities using VMDR 2.0
- Identify Vulnerable Assets using Qualys Threat Protection
- Recommendations & Mitigations
- Contributors
On October 6, 2022, the United States National Security Agency (NSA) released a cybersecurity advisory on the Chinese government—officially known as the People’s Republic of China (PRC) states-sponsored cyber actors’ activity to seek national interests. These malicious cyber activities attributed to the Chinese government targeted, and persist to target, a mixture of industries and organizations in the United States. They provide the top CVEs used since 2020 by the People’s Republic of China (PRC) states-sponsored cyber actors as evaluated by the National Security Agency (NSA), Cybersecurit
Tenable
Top 20 CVEs Exploited by People's Republic of China State-Sponsored Actors (AA22-279A)
blogs_tenable·2022-10-07
Top 20 CVEs Exploited by People's Republic of China State-Sponsored Actors (AA22-279A)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
blogs_tenable·2022-09-15
AA22-257A: Cybersecurity Agencies Issue Joint Advisory on Iranian Islamic Revolutionary Guard Corps-Affiliated Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
CISA Alert: Top 15 Routinely Exploited Vulnerabilities
blogs_qualys·2022-05-06·CVSS 10.0
[CRITICAL] CISA Alert: Top 15 Routinely Exploited Vulnerabilities
## Table of Contents
CISAs Top 15 Routinely Exploited Vulnerabilities of 2021
Highlights of Top Vulnerabilities Cited in CISA 2021 Report
Log4Shell Vulnerability
ProxyShell: Multiple Vulnerabilities
ProxyLogon: Multiple Vulnerabilities
How Can Qualys Help?
Getting Started
The U.S. Cybersecurity & Infrastructure Security Agency has published its report on the top exploited vulnerabilities of 2021. This blog summarizes the report’s findings and how you can use Qualys VMDR to automatically detect and remediate these risks in your enterprise environment.
The Cybersecurity & Infrastructure Security Agency (CISA) releases detailed alerts of critical vulnerabilities and threats when warranted. These alerts cover the most exploited security vulnerabilities and provide critical insights in
Qualys
CISA Alert: Top 15 Routinely Exploited Vulnerabilities | Qualys
blogs_qualys·2022-05-06
CISA Alert: Top 15 Routinely Exploited Vulnerabilities | Qualys
#### Table of Contents
- CISAs Top 15 Routinely Exploited Vulnerabilities of 2021
- Highlights of Top Vulnerabilities Cited in CISA 2021 Report
- Log4Shell Vulnerability
- ProxyShell: Multiple Vulnerabilities
- ProxyLogon: Multiple Vulnerabilities
- How Can Qualys Help?
- Getting Started
The U.S. Cybersecurity & Infrastructure Security Agency has published its report on the top exploited vulnerabilities of 2021. This blog summarizes the report’s findings and how you can use Qualys VMDR to automatically detect and remediate these risks in your enterprise environment.
The Cybersecurity & Infrastructure Security Agency (CISA) releases detailed alerts of critical vulnerabilities and threats when warranted. These alerts cover the most exploited security vulnerabilities and provide critical i
Sentinelone
Enterprise Security Essentials | Top 15 Most Routinely Exploited Vulnerabilities 2022
blogs_sentinelone·2022-04-28·CVSS 9.8
[CRITICAL] Enterprise Security Essentials | Top 15 Most Routinely Exploited Vulnerabilities 2022
From remote code execution and privilege escalation to security bypasses and path traversal, software vulnerabilities are a threat actor’s stock-in-trade for initial access and compromise. In the past 12 months, we’ve seen a number of new flaws, including Log4Shell, ProxyShell, and ProxyLogon, being exploited in attacks against enterprises. These and other known bugs, some revealed as far back as 2017, continue to be routinely abused in environments where organizations have failed to properly inventory and patch. As CISA released its latest update on the most commonly exploited vulnerabilities, we take a look at each of the top 15 most routinely exploited bugs being used against businesses today.
## 1. Log4Shell (CVE-2021-44228)
Occupying top spot is the notorious flaw in the Apache Java
Sentinelone
Enterprise Security Essentials | Top 15 Most Routinely Exploited Vulnerabilities 2022
blogs_sentinelone·2022-04-28·CVSS 9.8
[CRITICAL] Enterprise Security Essentials | Top 15 Most Routinely Exploited Vulnerabilities 2022
From remote code execution and privilege escalation to security bypasses and path traversal, software vulnerabilities are a threat actor’s stock-in-trade for initial access and compromise. In the past 12 months, we’ve seen a number of new flaws, including Log4Shell, ProxyShell, and ProxyLogon, being exploited in attacks against enterprises. These and other known bugs, some revealed as far back as 2017, continue to be routinely abused in environments where organizations have failed to properly inventory and patch. As CISA released its latest update on the most commonly exploited vulnerabilities, we take a look at each of the top 15 most routinely exploited bugs being used against businesses today .
## 1. Log4Shell (CVE-2021-44228)
Occupying top spot is the notorious flaw in the Apache Jav
Qualys
Russia-Ukraine Crisis: How to Strengthen Your Security Posture to Protect against Cyber Attack, based on CISA Guidelines
blogs_qualys·2022-02-26
Russia-Ukraine Crisis: How to Strengthen Your Security Posture to Protect against Cyber Attack, based on CISA Guidelines
## Table of Contents
Protecting Customer Data on Qualys Cloud Platform
Urgent: Assess and Heighten Your Security Posture
Step 1: Monitor Your Shodan/Internet Exposed Assets
Step 2: Detect, Prioritize and Remediate CISAs Catalog ofKnown Exploited Vulnerabilities
Step 3: Protect Your Cloud Services and Office 365
Step 4: Continuously Detect any Potential Threats and Attacks
Take Action to Learn More about How to Strengthen Your Defenses
CISA has created Shields Up as a response to the Russian invasion of Ukraine. Qualys is responding with additional security, monitoring and governance measures. This blog details how and what our enterprise customers can do to immediately strengthen their security posture and meet CISA’s recommendations.
With the invasion of Ukraine by Russia, the U.
Tenable
Government Advisories Warn of APT Activity Resulting from Russian Invasion of Ukraine
blogs_tenable·2022-02-24
Government Advisories Warn of APT Activity Resulting from Russian Invasion of Ukraine
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Qualys
CISA Alert: Top Routinely Exploited Vulnerabilities | Qualys
blogs_qualys·2021-07-29·CVSS 10.0
[CRITICAL] CISA Alert: Top Routinely Exploited Vulnerabilities | Qualys
#### Table of Contents
- Top Routinely Exploited Vulnerabilities
- Detect CISAs Top Routinely Exploited Vulnerabilities using Qualys VMDR
- Recommendations
- Remediation and Mitigation
- Get Started Now
On July 28, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a cybersecurity advisory detailing the top 30 publicly known vulnerabilities that have been routinely exploited by cyber threat actors in 2020 and 2021. Organizations are advised to prioritize and apply patches or workarounds for these vulnerabilities as soon as possible.
The advisory states, “If an organization is unable to update all software shortly after a patch is released, prioritize implementing patches for CVEs that are already known to be exploited or that would be accessible to the large
Qualys
CISA Alert: Top Routinely Exploited Vulnerabilities
blogs_qualys·2021-07-29·CVSS 9.1
[CRITICAL] CISA Alert: Top Routinely Exploited Vulnerabilities
## Table of Contents
Top Routinely Exploited Vulnerabilities
Detect CISAs Top Routinely Exploited Vulnerabilities using Qualys VMDR
Recommendations
Remediation and Mitigation
Get Started Now
On July 28, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a cybersecurity advisory detailing the top 30 publicly known vulnerabilities that have been routinely exploited by cyber threat actors in 2020 and 2021. Organizations are advised to prioritize and apply patches or workarounds for these vulnerabilities as soon as possible.
The advisory states, “If an organization is unable to update all software shortly after a patch is released, prioritize implementing patches for CVEs that are already known to be exploited or that would be accessible to the largest numbe
Securelist
Black Kingdom ransomware
blogs_securelist·2021-06-17·CVSS 10.0
CVE-2021-27065 [CRITICAL] Black Kingdom ransomware
Table of Contents
- Background
- Technical analysis
- Victims
- Attribution
- Appendix I – Indicators of Compromise
- Appendix II – MITRE ATT&CK Mapping
Authors
- Marc Rivero
## Python-coded malware used in Microsoft Exchange Server exploitation
Black Kingdom ransomware appeared on the scene back in 2019, but we observed some activity again in 2021. The ransomware was used by an unknown adversary for exploiting a Microsoft Exchange vulnerability (CVE-2021-27065).
The complexity and sophistication of the Black Kingdom family cannot bear a comparison with other Ransomware-as-a-Service (RaaS) or Big Game Hunting (BGH) families. The ransomware is coded in Python and compiled to an executable using PyInstaller; it supports two encryption modes: one generated dynamically and one using a h
Securelist
Black Kingdom ransomware
blogs_securelist·2021-06-17·CVSS 7.8
[HIGH] Black Kingdom ransomware
Table of Contents
Background
Technical analysis
Delivery methods
Sleep parameters
Ransomware is written in Python
Excluded directories
PowerShell command for process termination and history deletion
Encryption process
Encryption mistakes
System log cleanup
Ransomware note
Code analysis
Victims
Attribution
Appendix I – Indicators of Compromise
Appendix II – MITRE ATT&CK Mapping
Authors
Marc Rivero
## Python-coded malware used in Microsoft Exchange Server exploitation
Black Kingdom ransomware appeared on the scene back in 2019, but we observed some activity again in 2021. The ransomware was used by an unknown adversary for exploiting a Microsoft Exchange vulnerability (CVE-2021-27065).
The complexity and sophistication of the Black Kingdom family cannot bear a comparison
Talos
Quarterly Report: Incident Response trends from Spring 2021
blogs_talos·2021-06-10·CVSS 9.1
CVE-2021-26855 [CRITICAL] Quarterly Report: Incident Response trends from Spring 2021
## Quarterly Report: Incident Response trends from Spring 2021
By David Liebenberg and Caitlin Huey .
While the security community made a great effort to warn users of the exploitation of several Microsoft Exchange Server zero-day vulnerabilities , it was still the biggest threat Cisco Talos Incident Response (CTIR) saw this past quarter. These vulnerabilities, tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065, comprised around 35 percent of all incidents investigated.
This shows that when a vulnerability is recently disclosed, severe, and widespread, CTIR will often see a corresponding rise in engagements in which the vulnerabilities in question are involved. Thankfully, the majority of these incidents involved scanning and not post-compromise behavior, such
Talos
Quarterly Report: Incident Response trends from Spring 2021
blogs_talos·2021-06-10·CVSS 9.1
CVE-2021-26855 [CRITICAL] Quarterly Report: Incident Response trends from Spring 2021
By David Liebenberg and Caitlin Huey.
While the security community made a great effort to warn users of the exploitation of several Microsoft Exchange Server zero-day vulnerabilities, it was still the biggest threat Cisco Talos Incident Response (CTIR) saw this past quarter. These vulnerabilities, tracked as CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065, comprised around 35 percent of all incidents investigated.
This shows that when a vulnerability is recently disclosed, severe, and widespread, CTIR will often see a corresponding rise in engagements in which the vulnerabilities in question are involved. Thankfully, the majority of these incidents involved scanning and not post-compromise behavior, such as file encryption or evidence of exfiltration.
While CTIR’s focu
Securelist
IT threat evolution Q1 2021
blogs_securelist·2021-05-31
IT threat evolution Q1 2021
Table of Contents
Targeted attacks
Putting the ‘A’ into APT
Lazarus targets the defence industry
MS Exchange zero-day vulnerabilities exploited in the wild
Ecipekac: sophisticated multi-layered loader discovered in A41APT campaign
Other malware
Fake ad blocker, with miner included
Ransomware encrypting virtual hard disks
macOS developments
Secondhand news
Stalkerware during the pandemic
Doxing in the corporate sector
Authors
David Emm
## Targeted attacks
## Putting the ‘A’ into APT
In December, SolarWinds, a well-known IT managed services provider, fell victim to a sophisticated supply-chain attack. The company’s Orion IT, a solution for monitoring and managing customers’ IT infrastructure, was compromised by threat actors. This resulted in the deployment of a custom backd
Securelist
IT threat evolution Q1 2021. Non-mobile statistics
blogs_securelist·2021-05-31
IT threat evolution Q1 2021. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Attack geography
Top 10 most common families of ransomware Trojans
Miners
Number of new modifications
Number of users attacked by miners
Attack geography
Vulnerable applications used by cybercriminals during cyber attacks
Attacks on macOS
Threat geography
IoT attacks
IoT threat statistics
SSH-based attacks
Threats loaded into traps
Attacks via web resources
Countries that are sources of web-based attacks: Top 10
Countries where users faced the greatest risk of online infection
Local threats
Countries where users faced the highest risk of local infection
Autho
Securelist
IT threat evolution Q1 2021. Non-mobile statistics
blogs_securelist·2021-05-31
IT threat evolution Q1 2021. Non-mobile statistics
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyber attacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
These statistics are based on detection verdicts of Kaspersky products received from users who consented to provide statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q1 2021:
- Kaspersky solutions blocked 2,023,556,082 attacks launched from online resources across the globe.
- 613,968,631 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempts to run malware designed to steal money via online access to bank accounts were stopped on the computers of 118,099 users.
- Ransomware att
Securelist
IT threat evolution Q1 2021
blogs_securelist·2021-05-31
IT threat evolution Q1 2021
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
## Targeted attacks
### Putting the ‘A’ into APT
In December, SolarWinds, a well-known IT managed services provider, fell victim to a sophisticated supply-chain attack. The company’s Orion IT, a solution for monitoring and managing customers’ IT infrastructure, was compromised by threat actors. This resulted in the deployment of a custom backdoor, named Sunburst, on the networks of more than 18,000 SolarWinds customers, including many large corporations and government bodies, in North America, Europe, the Middle East and Asia.
One thing that sets this campaign apart from others, is the peculiar victim profiling and validation scheme. Out of the 18,000 Orion IT customers affected by the malware, it seems that on
Securelist
Kaspersky Security Bulletin 2020-2021. EU statistics
blogs_securelist·2021-05-26
Kaspersky Security Bulletin 2020-2021. EU statistics
Table of Contents
- Main figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
- Phishing in the EU
Authors
- Kaspersky
All statistics in this report are from the global cloud service Kaspersky Security Network (KSN), which receives information from components in our security solutions. The data was obtained from users who have given their consent to it being sent to KSN. Millions of Kaspersky users around the globe assist us in this endeavor to collect information about malicious activity. The statistics in this report cover the period from May 2020 to April 2021, inclusive.
## Main figures
- 70% of Internet user computers in the EU experienced at least
Securelist
Kaspersky Security Bulletin 2020-2021. EU statistics
blogs_securelist·2021-05-26
Kaspersky Security Bulletin 2020-2021. EU statistics
Table of Contents
Main figures
Financial threats
Number of users attacked by banking malware
Threat geography
Ransomware programs
Number of users attacked by ransomware Trojans
Threat geography
Top 10 most common families of ransomware Trojans
Miners
Number of users attacked by miners in the EU
Threat geography
Vulnerable applications used by cybercriminals
Attacks on macOS
Threat geography
IoT attacks
IoT threat statistics
Malware loaded into honeypots
Attacks via web resources
Countries that are sources of web-based attacks
Countries where users faced the greatest risk of online infection
Top 20 malicious programs most actively used in online attacks
Local threats
Countries where users faced the highest risk of local infection
Top 20 malicious objects detected on
Talos
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs
blogs_talos·2021-05-07
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs
By Caitlin Huey and Andrew Windsor with contributions from Edmund Brumaghin.
- Lemon Duck continues to refine and improve upon their tactics, techniques and procedures as they attempt to maximize the effectiveness of their campaigns.
- Lemon Duck remains relevant as the operators begin to target Microsoft Exchange servers, exploiting high-profile security vulnerabilities to drop web shells and carry out malicious activities.
- Lemon Duck continues to incorporate new tools, such as Cobalt Strike, into their malware toolkit.
- Additional obfuscation techniques are now being used to make the infrastructure associated with these campaigns more difficult to identify and analyze.
- The use of fake domains on East Asian top-level domains (TLDs) masks connections to the actual command and control
Talos
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs
blogs_talos·2021-05-07
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs
## Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPs
By Caitlin Huey and Andrew Windsor with contributions from Edmund Brumaghin .
Lemon Duck continues to refine and improve upon their tactics, techniques and procedures as they attempt to maximize the effectiveness of their campaigns.
Lemon Duck remains relevant as the operators begin to target Microsoft Exchange servers, exploiting high-profile security vulnerabilities to drop web shells and carry out malicious activities.
Lemon Duck continues to incorporate new tools, such as Cobalt Strike, into their malware toolkit.
Additional obfuscation techniques are now being used to make the infrastructure associated with these campaigns more difficult to identify and analyze.
The use of fake domain
Unit42
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of Credentials
blogs_unit42·2021-04-15·CVSS 9.1
CVE-2021-26855 [CRITICAL] Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of Credentials
Threat Research Center
Threat Research
Vulnerabilities
## Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of Credentials
Robert Falcone
Published: April 15, 2021
Threat Research
Vulnerabilities
Credential Harvesting
CVE-2021-26855
CVE-2021-26857
CVE-2021-26858
CVE-2021-27065
Microsoft Exchange Server
Webshell
## Executive Summary
The recently discovered and patched Microsoft Exchange vulnerabilities ( CVE-2021-26855 , CVE-2021-26857 , CVE-2021-26858 and CVE-2021-27065 ) have garnered considerable attention due to their mass exploitation and the severity of impact each exploitation has on the affected organization. On March 6, 2021, an unknown actor exploited vulnerabilities in Microsoft Exchange Server to install a webshell on a se
Unit42
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of Credentials
blogs_unit42·2021-04-15·CVSS 9.1
CVE-2021-26855 [CRITICAL] Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of Credentials
## Executive Summary
The recently discovered and patched Microsoft Exchange vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065) have garnered considerable attention due to their mass exploitation and the severity of impact each exploitation has on the affected organization. On March 6, 2021, an unknown actor exploited vulnerabilities in Microsoft Exchange Server to install a webshell on a server at a financial institution in the EMEA (Europe, the Middle East and Africa) region. While we did not have access to the webshell itself, the webshell is likely a variant of the China Chopper server-side JScript.
Six days after installing the webshell on March 12, 2021, the actor used the installed webshell to run PowerShell commands to gather information from the l
Tenable
Microsoft’s April 2021 Patch Tuesday Addresses 108 CVEs (CVE-2021-28310)
blogs_tenable·2021-04-13·CVSS 7.8
[HIGH] Microsoft’s April 2021 Patch Tuesday Addresses 108 CVEs (CVE-2021-28310)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
blogs_trendmicro·2021-04-09
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
APT & Targeted Attacks
# Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
This blog details how Iron Tiger threat actors have updated their toolkit with an updated SysUpdate malware variant that now uses five files in its infection routine instead of the usual three.
By: Daniel Lunghi, Kenney Lu
2021/04/09
Read time: ( words)
Save to Folio
Update as of April 27, 2021, 7 A.M. E.T.: We've updated the "Rootkits From a Public Repository" section and the appendix to include a second sample.
More than a year after Operation DRBControl, a campaign by a cyberespionage group that targets gambling and betting companies in Southeast Asia, we found evidence that the Iron Tiger threat actor is still interested in the gambling industry.
This blog details how Iron Tiger threat actors
Tenable
Microsoft Exchange Server ProxyLogon/Hafnium Detection Dashboard
blogs_tenable·2021-03-18·CVSS 9.1
CVE-2021-26855 [CRITICAL] Microsoft Exchange Server ProxyLogon/Hafnium Detection Dashboard
by Josef Weiss March 18, 2021
A series of Microsoft Exchange server zero-day exploits were discovered in December of 2020 by a Taiwanese organization called DEVCORE. The flaw, a server-side request forgery vulnerability, gives an attacker the ability to bypass authentication and gain elevated privileges. This vulnerability resulted in the issuance of CVE-2021-26855. An attack chain can be created by combining this vulnerability with an insecure deserialization vulnerability within the Exchange Unified Messaging Service (CVE-2021-26857), and multiple post authentication vulnerabilities (CVE-2021-26858 and CVE-2021-27065). A successful attack can lead to remote code execution, backdoors, and data theft, resulting in further potential compromise.
On March 2, 2021 Microsoft released critical
Tenable
How to Identify Compromised Microsoft Exchange Server Assets Using Tenable
blogs_tenable·2021-03-18
How to Identify Compromised Microsoft Exchange Server Assets Using Tenable
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft Exchange Server ProxyLogon/Hafnium Detection Report
blogs_tenable·2021-03-18·CVSS 9.1
CVE-2021-26855 [CRITICAL] Microsoft Exchange Server ProxyLogon/Hafnium Detection Report
by Ryan Seguin March 18, 2021
A series of Microsoft Exchange server zero-day exploits were discovered in December of 2020 by a Taiwanese organization called DEVCORE. The flaw, a server-side request forgery vulnerability, gives and attacker the ability to bypass authentication and gain elevated privileges. This vulnerability resulted in the issuance of CVE-2021-26855. An attack chain can be created by combining this vulnerability with an insecure deserialization vulnerability within the Exchange Unified Messaging Service (CVE-2021-26857), and multiple post authentication vulnerabilities (CVE-2021-26858 and CVE-2021-27065). A successful attack can lead to remote code execution, backdoors, and data theft, resulting in further potential compromise.
On March 2, 2021 Microsoft released critica
Fortinet
New DearCry Ransomware Targets Microsoft Exchange Server Vulnerabilities | FortiGuard Labs
blogs_fortinet·2021-03-12·CVSS 9.1
[CRITICAL] New DearCry Ransomware Targets Microsoft Exchange Server Vulnerabilities | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
New DearCry Ransomware Targets Microsoft Exchange Server Vulnerabilities
By FortiGuard Labs | March 12, 2021
FortiGuard Labs Breaking Update
FortiGuard Labs is currently tracking multiple reports of a new ransomware campaign, known as DearCry. This malware campaign targets the same four Microsoft Exchange Server vulnerabilities we reported on last week that were exploited by a number of threat actors, including the Chinese nation-state group known as Hafnium.
The four vulnerabilities being targeted by DoejoCrypt/DearCry are CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065. The attack chain targets a Microsoft Exchange server able to receive untrusted connections from an external source. Once installed, the DearCry ransomware creates enc
Unit42
Microsoft Exchange Server Attack Timeline
blogs_unit42·2021-03-11·CVSS 9.1
CVE-2021-26855 [CRITICAL] Microsoft Exchange Server Attack Timeline
## Executive Summary
On March 2, the world was introduced to four critical zero-day vulnerabilities impacting multiple versions of Microsoft Exchange Server (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065). Alongside revealing these vulnerabilities, Microsoft published security updates and technical guidance that stressed the importance of patching immediately, while concurrently noting active and ongoing exploitation by an Advanced Persistent Threat (APT) they call HAFNIUM. Since the initial attacks, Unit 42 and a number of other threat intelligence teams have seen multiple threat groups now exploiting these zero-day vulnerabilities in the wild. Both the vulnerabilities themselves and the access that can be achieved by exploiting them are significant. It is therefore u
Unit42
Microsoft Exchange Server Attack Timeline
blogs_unit42·2021-03-11·CVSS 9.1
CVE-2021-26855 [CRITICAL] Microsoft Exchange Server Attack Timeline
Threat Research Center
Threat Research
Vulnerabilities
## Microsoft Exchange Server Attack Timeline
Unit 42
Published: March 11, 2021
Malware
Threat Research
Vulnerabilities
CVE-2021-26855
CVE-2021-26857
CVE-2021-27065
Hafnium
Microsoft Exchange Server
## Executive Summary
On March 2, the world was introduced to four critical zero-day vulnerabilities impacting multiple versions of Microsoft Exchange Server ( CVE-2021-26855 , CVE-2021-26857 , CVE-2021-26858 and CVE-2021-27065 ). Alongside revealing these vulnerabilities, Microsoft published security updates and technical guidance that stressed the importance of patching immediately, while concurrently noting active and ongoing exploitation by an Advanced Persistent Threat (APT) they call HAFNIUM . Since the initial attack
Tenable
Healthcare Security: Ransomware Plays a Prominent Role in COVID-19 Era Breaches
blogs_tenable·2021-03-10
Healthcare Security: Ransomware Plays a Prominent Role in COVID-19 Era Breaches
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Hafnium Update: Continued Microsoft Exchange Server Exploitation
blogs_talos·2021-03-10
Hafnium Update: Continued Microsoft Exchange Server Exploitation
Update 3/11: The following OSQuery detects active commands being run through webshells observed used by actors on compromised Exchange servers. While systems may have been patched to defend against Hafnium and others, threat actors may have leveraged these vulnerabilities to establish additional persistence in victim networks. A thorough forensic investigation will be required to determine additional compromises.
It's been a week since Microsoft first disclosed several zero-day vulnerabilities in Exchange Server — and the scope has only grown since then. In its disclosure, Microsoft stated that a new threat actor known as Hafnium was exploiting these vulnerabilities to steal emails.
Since Microsoft's initial disclosure, Cisco Talos has seen shifts in the tactics, techniques, and procedur
Trendmicro
March Patch Tuesday: Fixes for Exchange Server, IE
blogs_trendmicro·2021-03-10·CVSS 9.1
[CRITICAL] March Patch Tuesday: Fixes for Exchange Server, IE
# March Patch Tuesday: Fixes for Exchange Server, IE
This month’s Patch Tuesday includes fixes already released for the Microsoft Exchange Server zero-day flaws attributed to Hafnium attacks.
By: Trend Micro
2021/03/10
Read time: ( words)
Save to Folio
This month’s Patch Tuesday features close to a hundred fixes, almost doubling last month’s total. The list includes patches already released for the Microsoft Exchange Server zero-day flaws attributed to Hafnium attacks.
Out of 89 patches released, 14 were rated Critical while the rest were deemed Important. Most of the critical vulnerabilities involve remote code execution (RCE) link except for an information disclosure bug. Fifteen of these were reported by the Zero Day Initiative (ZDI).
Microsoft Exchange Server Vulnerabilities
Th
Talos
Hafnium Update: Continued Microsoft Exchange Server Exploitation
blogs_talos·2021-03-10
Hafnium Update: Continued Microsoft Exchange Server Exploitation
## Hafnium Update: Continued Microsoft Exchange Server Exploitation
Update 3/11 : The following OSQuery detects active commands being run through webshells observed used by actors on compromised Exchange servers. While systems may have been patched to defend against Hafnium and others, threat actors may have leveraged these vulnerabilities to establish additional persistence in victim networks. A thorough forensic investigation will be required to determine additional compromises.
It's been a week since Microsoft first disclosed several zero-day vulnerabilities in Exchange Server — and the scope has only grown since then. In its disclosure, Microsoft stated that a new threat actor known as Hafnium was exploiting these vulnerabilities to steal emails.
Since Microsoft's initial disclosure
Unit42
Remediation Steps for the Microsoft Exchange Server Vulnerabilities
blogs_unit42·2021-03-09·CVSS 9.1
CVE-2021-26855 [CRITICAL] Remediation Steps for the Microsoft Exchange Server Vulnerabilities
Threat Research Center
Threat Research
Vulnerabilities
## Remediation Steps for the Microsoft Exchange Server Vulnerabilities
Unit 42
Published: March 9, 2021
Threat Research
Vulnerabilities
CVE-2021-26855
CVE-2021-26857
CVE-2021-26858
CVE-2021-27065
Microsoft Exchange Server
## Background
On March 2, the security community became aware of four critical zero-day Microsoft Exchange Server vulnerabilities ( CVE-2021-26855 , CVE-2021-26857 , CVE-2021-26858 and CVE-2021-27065 ).
These vulnerabilities let adversaries access Exchange Servers and potentially gain long-term access to victims’ environments. While the Microsoft Threat Intelligence Center (MSTIC) attributes the initial campaign with high confidence to HAFNIUM , a group they assess to be state-sponsored and operatin
Tenable
Microsoft’s March 2021 Patch Tuesday Addresses 82 CVEs (CVE-2021-26411)
blogs_tenable·2021-03-09·CVSS 8.8
[HIGH] Microsoft’s March 2021 Patch Tuesday Addresses 82 CVEs (CVE-2021-26411)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Remediation Steps for the Microsoft Exchange Server Vulnerabilities
blogs_unit42·2021-03-09·CVSS 9.1
CVE-2021-26855 [CRITICAL] Remediation Steps for the Microsoft Exchange Server Vulnerabilities
## Background
On March 2, the security community became aware of four critical zero-day Microsoft Exchange Server vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065).
These vulnerabilities let adversaries access Exchange Servers and potentially gain long-term access to victims’ environments. While the Microsoft Threat Intelligence Center (MSTIC) attributes the initial campaign with high confidence to HAFNIUM, a group they assess to be state-sponsored and operating out of China, multiple threat intelligence teams, including MSTIC and Unit 42, are also seeing multiple threat actors now exploiting these zero-day vulnerabilities in the wild. Estimated number of potentially compromised organizations is in the tens of thousands globally – and very importantly, t
Fortinet
Fortinet Addresses Latest Microsoft Exchange Server Exploits | FortiGuard Labs
blogs_fortinet·2021-03-08·CVSS 9.1
[CRITICAL] Fortinet Addresses Latest Microsoft Exchange Server Exploits | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Fortinet Addresses Latest Microsoft Exchange Server Exploits
By FortiGuard Labs | March 08, 2021
As many as 30,000 businesses and government agencies across the US have been targeted by an aggressive hacking campaign that exploits vulnerabilities in versions of Microsoft Exchange Server, with some experts claiming that “hundreds of thousands” of Exchange Servers have been exploited worldwide. Microsoft is attributing these exploits to a cyber espionage organization known as HAFNIUM, operating out of mainland China.
Microsoft Exchange Server is used by millions of organizations for email and calendar, as well as a collaboration solution. This exploit vector targets Microsoft Exchange Servers able to receive untrusted connections from an external source. Am
Tenable
Finding Proxylogon and Related Microsoft Exchange Vulnerabilities: How Tenable Can Help
blogs_tenable·2021-03-08
Finding Proxylogon and Related Microsoft Exchange Vulnerabilities: How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
SentinelOne and HAFNIUM / Microsoft Exchange 0-days
blogs_sentinelone·2021-03-04
SentinelOne and HAFNIUM / Microsoft Exchange 0-days
On Tuesday, March 2nd, Microsoft released an out-of-band security update addressing a total of 7 CVEs, four of which are associated with ongoing, targeted attacks. The update was in response to an active campaign that was seen on Microsoft clients compromising Exchange servers by bypassing authentication and allowing attackers to read emails and potentially penetrate enterprise networks without the need to authenticate.
The SentinelLabs team has been closely tracking HAFNIUM and Exchange Server impacts. Customers with the Deep Visibility threat hunting module (STAR) may also automate responses (alerts, network quarantine, kill, quarantine) should these IoCs be seen in the future. Our customers can stay ahead of this emerging threat with our protection capabilities and real-time alerts.
#
Talos
Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
blogs_talos·2021-03-04·CVSS 9.1
CVE-2021-26855 [CRITICAL] Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
Microsoft released patches for four vulnerabilities in Exchange Server on March 2, disclosing that these vulnerabilities were being exploited by a previously unknown threat actor, referred to as HAFNIUM.
The vulnerabilities in question — CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065 — affect Microsoft Exchange Server 2019, 2016, 2013 and the out-of-support Microsoft Exchange Server 2010. The patches for these vulnerabilities should be applied as soon as possible. Microsoft Exchange Online is not affected.
Patches for an additional three vulnerabilities in the same software have also been released: CVE-2021-26412, CVE-2021-26854 and CVE-2021-27078. It is believed that these vulnerabilities have not yet been exploited in the wild.
## Threat activity details
The threat
Securelist
Zero-day vulnerabilities in Microsoft Exchange Server
blogs_securelist·2021-03-04·CVSS 9.1
[CRITICAL] Zero-day vulnerabilities in Microsoft Exchange Server
Table of Contents
What happened?
How to protect against this threat?
Recommendations
Authors
Vladimir Kuskov
Alexey Kulaev
Nikita Galimov
## What happened?
On March 2, 2021 several companies released reports about in-the-wild exploitation of zero-day vulnerabilities inside Microsoft Exchange Server. The following vulnerabilities allow an attacker to compromise a vulnerable Microsoft Exchange Server. As a result, an attacker will gain access to all registered email accounts, or be able to execute arbitrary code (remote code execution or RCE) within the Exchange Server context. In the latter case, the attacker will also be able to achieve persistence on the infected server.
A total of four vulnerabilities were uncovered:
CVE-2021-26855 . Server-side request forgery (SSRF) allows a
Talos
Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
blogs_talos·2021-03-04·CVSS 9.1
CVE-2021-26855 [CRITICAL] Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
## Threat Advisory: HAFNIUM and Microsoft Exchange zero-day
Microsoft released patches for four vulnerabilities in Exchange Server on March 2, disclosing that these vulnerabilities were being exploited by a previously unknown threat actor, referred to as HAFNIUM .
The vulnerabilities in question — CVE-2021-26855 , CVE-2021-26857 , CVE-2021-26858 and CVE-2021-27065 — affect Microsoft Exchange Server 2019, 2016, 2013 and the out-of-support Microsoft Exchange Server 2010. The patches for these vulnerabilities should be applied as soon as possible. Microsoft Exchange Online is not affected.
Patches for an additional three vulnerabilities in the same software have also been released: CVE-2021-26412 , CVE-2021-26854 and CVE-2021-27078 . It is believed that these vulnerabilities have not yet b
Securelist
Zero-day vulnerabilities in Microsoft Exchange Server
blogs_securelist·2021-03-04·CVSS 9.1
[CRITICAL] Zero-day vulnerabilities in Microsoft Exchange Server
Table of Contents
- What happened?
- How to protect against this threat?
- Recommendations
Authors
- Vladimir Kuskov
- Alexey Kulaev
- Nikita Galimov
## What happened?
On March 2, 2021 several companies released reports about in-the-wild exploitation of zero-day vulnerabilities inside Microsoft Exchange Server. The following vulnerabilities allow an attacker to compromise a vulnerable Microsoft Exchange Server. As a result, an attacker will gain access to all registered email accounts, or be able to execute arbitrary code (remote code execution or RCE) within the Exchange Server context. In the latter case, the attacker will also be able to achieve persistence on the infected server.
A total of four vulnerabilities were uncovered:
1. CVE-2021-26855. Server-side request forgery (SSR
Sentinelone
SentinelOne and HAFNIUM / Microsoft Exchange 0-days
blogs_sentinelone·2021-03-04
SentinelOne and HAFNIUM / Microsoft Exchange 0-days
On Tuesday, March 2nd, Microsoft released an out-of-band security update addressing a total of 7 CVEs, four of which are associated with ongoing, targeted attacks. The update was in response to an active campaign that was seen on Microsoft clients compromising Exchange servers by bypassing authentication and allowing attackers to read emails and potentially penetrate enterprise networks without the need to authenticate.
The SentinelLabs team has been closely tracking HAFNIUM and Exchange Server impacts. Customers with the Deep Visibility threat hunting module (STAR) may also automate responses (alerts, network quarantine, kill, quarantine) should these IoCs be seen in the future. Our customers can stay ahead of this emerging threat with our protection capabilities and real-time alerts.
#
Unit42
Threat Assessment: Active Exploitation of Four Zero-Day Vulnerabilities in Microsoft Exchange Server
blogs_unit42·2021-03-03·CVSS 9.1
CVE-2021-26855 [CRITICAL] Threat Assessment: Active Exploitation of Four Zero-Day Vulnerabilities in Microsoft Exchange Server
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Assessment: Active Exploitation of Four Zero-Day Vulnerabilities in Microsoft Exchange Server
Unit 42
Published: March 3, 2021
High Profile Threats
Vulnerabilities
CVE-2021-26855
CVE-2021-26857
CVE-2021-26858
CVE-2021-27065
Exploits
Microsoft Exchange Server
Zero-day
## Executive Summary
On Mar. 2, 2021, Volexity reported in-the-wild-exploitation of four Microsoft Exchange Server vulnerabilities: CVE-2021-26855 , CVE-2021-26857 , CVE-2021-26858 and CVE-2021-27065 .
As a result of these vulnerabilities being exploited, adversaries can access Microsoft Exchange Servers and allow installation of additional tools to facilitate long-term access into victims' environments. There has also been a report of m
Zscaler
Coverage Advisory for Zero-day Exploits Related to MS-Office
blogs_zscaler·2021-03-03
Coverage Advisory for Zero-day Exploits Related to MS-Office
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Unit42
Threat Assessment: Active Exploitation of Four Zero-Day Vulnerabilities in Microsoft Exchange Server
blogs_unit42·2021-03-03·CVSS 9.1
CVE-2021-26855 [CRITICAL] Threat Assessment: Active Exploitation of Four Zero-Day Vulnerabilities in Microsoft Exchange Server
## Executive Summary
On Mar. 2, 2021, Volexity reported in-the-wild-exploitation of four Microsoft Exchange Server vulnerabilities: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065.
As a result of these vulnerabilities being exploited, adversaries can access Microsoft Exchange Servers and allow installation of additional tools to facilitate long-term access into victims' environments. There has also been a report of multiple threat actors leveraging these zero-day vulnerabilities, meaning post-exploitation activity may vary depending on the purpose of the different threat actors.
These vulnerabilities affect the following Microsoft Exchange Server versions:
- Microsoft Exchange 2013.
- Microsoft Exchange 2016.
- Microsoft Exchange 2019.
Microsoft has released an emerg
Qualys
Microsoft Exchange Server Zero-Days (ProxyLogon) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR
blogs_qualys·2021-03-03·CVSS 9.1
[CRITICAL] Microsoft Exchange Server Zero-Days (ProxyLogon) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR
## Table of Contents
CVE Technical Details
Attack Chain
Discover and Remediate the Zero-Day Vulnerabilities Using Qualys VMDR
Post-Compromise Detection Details
References
Update March 10, 2021 : A new section describes how to respond with mitigation controls if patches cannot be applied, as recommended by Microsoft. This section details the Qualys Policy Compliance control ids for each vulnerability.
Update March 8, 2021 : Qualys has released an additional QID: 50108 which remotely detects instances of Exchange Server vulnerable to ProxyLogon vulnerability CVE-2021-26855 without authentication. QID 50108 is available in VULNSIGS-2.5.125-3 version and above, and is available across all platforms as of March 8th, 1:38 AM ET. This QID is not applicable to agents, so the signature versi
Huntress
Rapid Response: Mass Exploitation of On-Prem Exchange Servers | Huntress
blogs_huntress·2021-03-03
Rapid Response: Mass Exploitation of On-Prem Exchange Servers | Huntress
UPDATED 14 April:
Huntress is aware of the new Microsoft Exchange vulnerabilities disclosed in the Microsoft April Security Update . Our team has yet to detect exploits targeting these new vulnerabilities on any hosts running the Huntress agent but will continue to closely monitor for these threats. These vulnerabilities are all branded as "critical" in severity and again offer remote code execution to an attacker. Considering the strong focus on Exchange by a large number of threat actors, it is absolutely imperative that organizations patch as quickly as they can. We recommend you update to the latest security patch , monitor for new indicators of compromise and stay up-to-date on new information as it releases. We will continue to update this post with new findings.
UPDATED 05 March @
Qualys
Microsoft Exchange Server Zero-Days (ProxyLogon) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR | Qualys
blogs_qualys·2021-03-03·CVSS 9.1
[CRITICAL] Microsoft Exchange Server Zero-Days (ProxyLogon) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR | Qualys
#### Table of Contents
- CVE Technical Details
- Attack Chain
- Discover and Remediate the Zero-Day Vulnerabilities Using Qualys VMDR
- Post-Compromise Detection Details
- References
Update March 10, 2021: A new section describes how to respond with mitigation controls if patches cannot be applied, as recommended by Microsoft. This section details the Qualys Policy Compliance control ids for each vulnerability.
Update March 8, 2021: Qualys has released an additional QID: 50108 which remotely detects instances of Exchange Server vulnerable to ProxyLogon vulnerability CVE-2021-26855 without authentication. QID 50108 is available in VULNSIGS-2.5.125-3 version and above, and is available across all platforms as of March 8th, 1:38 AM ET. This QID is not applicable to agents, so the signature
Krebs
Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder Emails
blogs_krebs·2021-03-02
Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder Emails
Microsoft Corp. today released software updates to plug four security holes that attackers have been using to plunder email communications at companies that use its Exchange Server products. The company says all four flaws are being actively exploited as part of a complex attack chain deployed by a previously unidentified Chinese cyber espionage group.
The software giant typically releases security updates on the second Tuesday of each month, but it occasionally deviates from that schedule when addressing active attacks that target newly identified and serious vulnerabilities in its products.
The patches released today fix security problems in Microsoft Exchange Server 2013 , 2016 and 2019 . Microsoft said its Exchange Online service — basically hosted email for businesses — is not impac
Tenable
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065: Four Zero-Day Vulnerabilities in Microsoft Exchange Server Exploited in the Wild
blogs_tenable·2021-03-02·CVSS 9.1
[CRITICAL] CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065: Four Zero-Day Vulnerabilities in Microsoft Exchange Server Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder Emails
blogs_krebs·2021-03-02
Microsoft: Chinese Cyberspies Used 4 Exchange Server Flaws to Plunder Emails
Microsoft Corp. today released software updates to plug four security holes that attackers have been using to plunder email communications at companies that use its Exchange Server products. The company says all four flaws are being actively exploited as part of a complex attack chain deployed by a previously unidentified Chinese cyber espionage group.
The software giant typically releases security updates on the second Tuesday of each month, but it occasionally deviates from that schedule when addressing active attacks that target newly identified and serious vulnerabilities in its products.
The patches released today fix security problems in Microsoft Exchange Server 2013, 2016 and 2019. Microsoft said its Exchange Online service — basically hosted email for businesses — is not impacte
Recorded Future
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange Servers
blogs_recorded_future·CVSS 9.1
[CRITICAL] Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange Servers
# Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange Servers
Beginning on March 1, 2021, Recorded Future’s Insikt Group identified a large increase in victim communications to PlugX command and control (C2) infrastructure publicly attributed to the suspected Chinese state-sponsored group Calypso APT. We believe that this activity is highly likely linked to the exploitation of recently disclosed Microsoft Exchange vulnerabilities (also known as ProxyLogon — CVE-2021-26855, CVE-2021-27065). Our observations align with recent reporting by ESET in which the group was identified targeting vulnerable Exchange servers to deploy a web shell and ultimately load the PlugX malware post-exploitation.
Targeted organizations were geographically widespread and covered multiple
Crowdstrike
Patch Tuesday 2021: A Vulnerability Deep Dive
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Patch Tuesday 2021: A Vulnerability Deep Dive
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Threat Intel
Magic Hound (Magic Hound, TA453, COBALT ILLUSION)
threat_intel·CVSS 9.1
[CRITICAL] Magic Hound (Magic Hound, TA453, COBALT ILLUSION)
# Threat Actor Profile: Magic Hound
ATT&CK ID: G0059
Also known as: Magic Hound, TA453, COBALT ILLUSION, Charming Kitten, ITG18, Phosphorus, Newscaster, APT35, Mint Sandstorm
Suspected origin: Iran
## Overview
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European, U.S., and Middle Eastern government and military personnel, academics, journalists, and organizations such as the World Health Organization (WHO), via complex social engineering campaigns since at least 2014.(Citation: FireEye APT35 2018)(Citation: ClearSky Kittens Back 3 August 2020)(Citation: Certfa Charming Kitten January 2021)(Citation: Secureworks COBALT ILLUSION Threat Pr
Huntress
Rapid Response: Mass Exploitation of On-Prem Exchange Servers | Huntress
blogs_huntress
Rapid Response: Mass Exploitation of On-Prem Exchange Servers | Huntress
UPDATED 14 April:
Huntress is aware of the new Microsoft Exchange vulnerabilities disclosed in the Microsoft April Security Update. Our team has yet to detect exploits targeting these new vulnerabilities on any hosts running the Huntress agent but will continue to closely monitor for these threats. These vulnerabilities are all branded as "critical" in severity and again offer remote code execution to an attacker. Considering the strong focus on Exchange by a large number of threat actors, it is absolutely imperative that organizations patch as quickly as they can. We recommend you update to the latest security patch, monitor for new indicators of compromise and stay up-to-date on new information as it releases. We will continue to update this post with new findings.
UPDATED 05 March @ 1
Crowdstrike
Patch Tuesday 2021: A Vulnerability Deep Dive
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Patch Tuesday 2021: A Vulnerability Deep Dive
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Huntress
Ten Years of Resilience, Innovation & Community-Driven Defense | Huntress
blogs_huntress·CVSS 8.8
[HIGH] Ten Years of Resilience, Innovation & Community-Driven Defense | Huntress
The world of cybersecurity has been a wild ride over the last decade. As attackers stepped up their game year over year, the security community responded and adapted with resilience and ingenuity to each new wave of threats.
Attackers tested our limits time and time again with bolder, more cutting-edge cyberattacks: ransomware, supply chain compromises, zero-day vulnerabilities, and more. But every single breach, compromise, and exploited vulnerability taught us something new, pushed us harder to innovate and stay steps ahead, brought our security community closer together, and rallied us to wreck hackers.
As we celebrate our 10th anniversary at Huntress this month, we’re pausing to look back at the events that have shaped the entire cybersecurity community. Understanding where we've bee
Recorded Future
2025 Cloud Threat Hunting and Defense Landscape
blogs_recorded_future
2025 Cloud Threat Hunting and Defense Landscape
# 2025 Cloud Threat Hunting and Defense Landscape
## Executive Summary
Insikt Group has observed continued trends of growth and increased activity of threat actors leveraging and exploiting cloud infrastructure to broaden the number of victims they target and infect. Recent reporting across the observed incidents shows that cloud-focused threats are converging on a few consistent patterns, which serve as the main sections of this report:
- Exploitation and Misconfiguration
- Cloud Abuse
- Cloud Ransomware
- Credential Abuse, Account Takeover, and Unauthorized Access
- Third-Party Compromise
Across cases, initial access frequently comes from vulnerable or misconfigured services exposed to the internet — including application delivery controllers, monitoring dashboards, email security ga
Crowdstrike
Falcon Complete Stops Microsoft Exchange Server Zero-Day Exploits
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Falcon Complete Stops Microsoft Exchange Server Zero-Day Exploits
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
Vapor Panda Adversary Profile
blogs_crowdstrike·CVSS 9.1
[CRITICAL] Vapor Panda Adversary Profile
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
Upcoming events
Conference
CrowdTour
Find a city near you
Summit
Day Zero 2026
Las Vegas, NV
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Blog
Contact us
Careers
Latest Innovations
## Vapor Panda
Discover the adversaries targeting your industry
Profile VAPOR PANDA is a China-based targeted intrusion adversary CrowdStrike Intelligence initially tracked under the VexatiousTemper activity cluster. The adversary was first identified in February 2021, when VAPOR PANDA leveraged the ProxyLogon exploit chain (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065). VAPOR PANDA has targeted think tanks, l
Crowdstrike
March 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] March 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Recorded Future
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange Servers
blogs_recorded_future·CVSS 9.1
[CRITICAL] Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange Servers
## Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange Servers
Beginning on March 1, 2021, Recorded Future’s Insikt Group identified a large increase in victim communications to PlugX command and control (C2) infrastructure publicly attributed to the suspected Chinese state-sponsored group Calypso APT. We believe that this activity is highly likely linked to the exploitation of recently disclosed Microsoft Exchange vulnerabilities (also known as ProxyLogon — CVE-2021-26855, CVE-2021-27065). Our observations align with recent reporting by ESET in which the group was identified targeting vulnerable Exchange servers to deploy a web shell and ultimately load the PlugX malware post-exploitation.
Targeted organizations were geographically widespread and covered multipl
Threat Intel
Threat Group-3390 (Threat Group-3390, Earth Smilodon, TG-3390)
threat_intel·CVSS 9.8
[CRITICAL] Threat Group-3390 (Threat Group-3390, Earth Smilodon, TG-3390)
# Threat Actor Profile: Threat Group-3390
ATT&CK ID: G0027
Also known as: Threat Group-3390, Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION, APT27, Iron Tiger, LuckyMouse, Linen Typhoon
Suspected origin: China
## Overview
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)
## Techniques (TTPs)
### Resource Development
- T1608.001 Upload Malware
Usage: Threat Group-3390 has hosted mal
arXiv
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
arxiv_fulltext·2022-08-17
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
An In-depth Study of Java Deserialization Remote-Code Execution Exploits and Vulnerabilities
[Imen Sayar]Imen Sayar^
[email protected]
University of Toulouse
Blagnac
France
31070
^ Part of this research was conducted when Imen Sayar was at the University of Luxembourg
[Alexandre Bartel]Alexandre Bartel^*
[email protected]
Umeå University
MIT-Huset
Umeå
Sweden
^*Part of this research was conducted when Alexandre Bartel was at the University of Luxembourg and the University of Copenhagen.
Eric Bodden
[email protected]
Paderborn University
Paderborn
Germany
Yves Le Traon
[email protected]
University of Luxembourg
6, rue Richard Coudenhove-Kalergi
Kirchberg Campus
Luxembourg
L-1359
## Abstract
Nowadays, an increasing number of applications uses deserializatio
arXiv
Multi-Level Fine-Tuning, Data Augmentation, and Few-Shot Learning for Specialized Cyber Threat Intelligence
arxiv_fulltext·2022-07-22
Multi-Level Fine-Tuning, Data Augmentation, and Few-Shot Learning for Specialized Cyber Threat Intelligence
Multi-Level Fine-Tuning, Data Augmentation, and Few-Shot Learning for Specialized Cyber Threat Intelligence
Specialized Cyber Threat Intelligence
Markus Bayer Tobias Frey Christian Reuter
Markus Bayer Tobias Frey Christian Reuter
Technical University of Darmstadt, Darmstadt, Germany
\bayer, frey, reuter\@peasec.tu-darmstadt.de
[email protected] [email protected] [email protected]
PEASEC - Science and Technology for Peace and Security
Technical University of Darmstadt
Pankratiusstraße 2, 64289 Darmstadt
Germany
[
@twocolumnfalse
## Abstract
Gathering cyber threat intelligence from open sources is becoming increasingly important for maintaining and achieving a high level of security as systems become larger and more complex.
However, the
2021-03-03
Published
2021-11-03
Added to CISA KEV
Exploited in the wild