Preventing Data Loss: Backup and Recovery Strategies for Exchange Server AdministratorsThe Hacker News·Jan 25, 16:22 UTC · Jan 25, 2024Ransomware60
Microsoft's End of Support for Exchange 2016 and 2019: What IT Teams Must Do NowThe Hacker News·Feb 20, 10:00 UTC · Feb 20, 2025Ransomware60
Almost 2,000 Exchange servers hacked using ProxyShell exploitThe Record·Dec 15, 00:00 UTC · Dec 15, 2022RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
Attacks on Exchange servers expand from nationThe Record·Nov 17, 06:58 UTC · Nov 17, 2022Ransomware in the wild60
Play ransomware attacks use a new exploit to bypass ProxyNotShell mitigations on Exchange serversSecurity Affairs·Dec 21, 23:26 UTC · Dec 21, 2022RansomwareCVE-2022-41040CVE-2022-41082CVE-2022-4108060
Microsoft shares one-click ProxyLogon mitigation tool for Exchange serversThe Record·Jan 24, 00:00 UTC · Jan 24, 2023RansomwareCVE-2021-2685560
CISA, NSA offer guidance to better protect Microsoft Exchange ServersCyberScoop·Oct 30, 22:00 UTC · Oct 30, 2025Ransomware in the wildCVE-2025-5378660
Attackers probing for vulnerable Microsoft Exchange Servers, is yours one of them?Help Net Security·Mar 1, 12:53 UTC · Mar 1, 2020RansomwareCVE-2020-068860
Concerns as Ransomware and Exchange Server Attacks SurgeInfosecurity Magazine·Mar 30, 11:25 UTC · Mar 30, 2021RansomwareCVE-2021-2706560
Hackers Are Targeting Microsoft Exchange Servers With RansomwareThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2021Ransomware in the wild60
Microsoft One-Click Tool Mitigates Exchange Server AttacksInfosecurity Magazine·Mar 16, 10:33 UTC · Mar 16, 2021Ransomware in the wildCVE-2021-2685560
LockBit affiliates compromise Microsoft Exchange servers to deploy ransomwareSecurity Affairs·Oct 12, 05:54 UTC · Oct 12, 2022RansomwareCVE-2022-21969CVE-2022-41040CVE-2022-4108260
Germany warns of ransomware attacks over Christmas, citing Emotet return, unpatched Exchange serversThe Record·Dec 21, 00:00 UTC · Dec 21, 2022Ransomware60
No signs yet of Exchange Server compromises at federal agencies, CISA saysCyberScoop·Mar 10, 20:08 UTC · Mar 10, 2021Ransomware in the wild60
A Basic Timeline of the Exchange Mass-HackKrebs on Security·Mar 8, 16:45 UTC · Mar 8, 2021Ransomware60
Conti ransomware gang targets Microsoft Exchange servers with ProxyShell exploitsSecurity Affairs·Sep 3, 17:00 UTC · Sep 3, 2021RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
At least 10 APT hacking groups have exploited Exchange Server bugs, ESET warnsCyberScoop·Mar 10, 16:25 UTC · Mar 10, 2021Ransomware in the wild60
FBI Removes Web Shells from Infected Exchange ServersInfosecurity Magazine·Apr 14, 09:30 UTC · Apr 14, 2021Ransomware in the wild60
Chinese Hackers Implant PlugX Variant on Compromised MS Exchange ServersThe Hacker News·Mar 23, 11:47 UTC · Mar 23, 2022Ransomware60
Quarterly Report: Incident Response trends from Spring 2021Cisco Talos·Jun 10, 12:00 UTC · Jun 10, 2021RansomwareCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
Botnet operators, ransomware scammers the latest groups to pounce on Exchange Server bugsCyberScoop·Mar 12, 17:07 UTC · Mar 12, 2021Ransomware in the wild60
New LockFile gang uses ProxyShell and PetitPotam exploitsSecurity Affairs·Aug 23, 20:02 UTC · Aug 23, 2021RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
German cyber agency warns 17,000 Microsoft Exchange servers are vulnerable to critical bugsThe Record·Mar 27, 17:02 UTC · Mar 27, 2024Ransomware in the wild60
As firms race to patch Microsoft Exchange flaws, security pros brace for ransomware outbreakCyberScoop·Mar 12, 19:28 UTC · Mar 12, 2021Ransomware in the wild60
NCSC: Install Latest Microsoft Exchange Server Updates UrgentlyInfosecurity Magazine·Mar 12, 16:35 UTC · Mar 12, 2021Ransomware60
Week in review: Attackers probing for vulnerable Exchange servers, RSA Conference 2020 coverageHelp Net Security·Mar 1, 00:00 UTC · Mar 1, 2020Ransomware in the wildCVE-2020-0688CVE-2020-6418CVE-2019-1512660
Researchers warn of a surge in cyber attacks against Microsoft ExchangeSecurity Affairs·Mar 12, 22:51 UTC · Mar 12, 2021Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft Exchange flaw CVE-2024Security Affairs·Feb 21, 07:33 UTC · Feb 21, 2024Ransomware in the wildCVE-2024-2141060
ProxyLogon Microsoft Exchange exploit is completely out of the bagSecurity Affairs·Mar 15, 12:56 UTC · Mar 15, 2021Ransomware in the wildCVE-2021-2685560
Mass Exploitation of Exchange Server ProxShell BugsInfosecurity Magazine·Aug 24, 10:27 UTC · Aug 24, 2021Ransomware in the wildCVE-2021-34473CVE-2021-34523CVE-2021-3120760
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
Exchange Server Attackers Launched Scans Within Five Minutes of DisclosureInfosecurity Magazine·May 20, 10:00 UTC · May 20, 2021Ransomware60
Hackers Exploit Apache HTTP Server Flaw to Deploy Linuxsys Cryptocurrency MinerThe Hacker News·Jul 21, 06:31 UTC · Jul 21, 2025RansomwareCVE-2021-41773CVE-2024-36401CVE-2023-22527+5 CVEs60
Threat Source Newsletter (April 15, 2021)Cisco Talos·Apr 15, 18:00 UTC · Apr 15, 2021RansomwareCVE-2021-28480CVE-2021-28481CVE-2021-28482+1 CVEs60
IKEA hit by a cyber attack that uses stolen internal replySecurity Affairs·Nov 27, 11:27 UTC · Nov 27, 2021RansomwareCVE-2021-26855CVE-2021-34473CVE-2021-3452360
Microsoft releases On-premises Mitigation Tool (EOMT) tool to fix ProxyLogon issuesSecurity Affairs·Mar 16, 08:27 UTC · Mar 16, 2021Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Hive Ransomware extorted over $100M in ransom payments from over 1,300 companiesSecurity Affairs·Nov 18, 11:39 UTC · Nov 18, 2022RansomwareCVE-2020-12812CVE-2021-31207CVE-2021-34473+1 CVEs60
Use This One-Click Mitigation Tool from Microsoft to Prevent Exchange AttacksThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2021Ransomware in the wildCVE-2021-2685560
Rackspace: Play Ransomware gang used a previously unknown exploit to access its Hosted Exchange email environmentSecurity Affairs·Jan 6, 15:29 UTC · Jan 6, 2023RansomwareCVE-2022-41040CVE-2022-41082CVE-2022-4108060