New LockFile gang uses ProxyShell and PetitPotam exploitsSecurity Affairs·Aug 23, 20:02 UTC · Aug 23, 2021RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
New Microsoft Exchange exploit chain lets ransomware attackers in (CVE-2022-41080)Help Net Security·Dec 21, 00:00 UTC · Dec 21, 2022Ransomware in the wildCVE-2022-41080CVE-2022-41082CVE-2022-41040160
Conti ransomware gang targets Microsoft Exchange servers with ProxyShell exploitsSecurity Affairs·Sep 3, 17:00 UTC · Sep 3, 2021RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
Black Kingdom is targeting Microsoft Exchange serversSecurity Affairs·Mar 24, 13:39 UTC · Mar 24, 2021Ransomware57
Microsoft Exchange vulnerabilities exploited once again for ransomware, this time with BabukCisco Talos·Nov 3, 12:00 UTC · Nov 3, 2021RansomwareCVE-2021-3694260
Black Kingdom Ransomware Hunting Unpatched Microsoft Exchange ServersThe Hacker News·Mar 25, 12:05 UTC · Mar 25, 2021Ransomware57
A hacking group is hijacking Microsoft Exchange web shellsThe Record·Nov 17, 00:00 UTC · Nov 17, 2022Ransomware57
WARNING: Microsoft Exchange Under Attack With ProxyShell FlawsThe Hacker News·Aug 23, 13:28 UTC · Aug 23, 2021Ransomware in the wildCVE-2021-34473CVE-2021-34523CVE-2021-3120760
Microsoft Exchange servers targeted by DearCry ransomware abusing ProxyLogon bugsThe Record·Nov 17, 00:00 UTC · Nov 17, 2022Ransomware57
Microsoft Exchange servers targeted by second ransomware groupThe Record·Nov 17, 00:00 UTC · Nov 17, 2022Ransomware57
Microsoft shares one-click ProxyLogon mitigation tool for Exchange serversThe Record·Jan 24, 00:00 UTC · Jan 24, 2023RansomwareCVE-2021-2685560
BlackCat Ransomware Gang Targeting Unpatched Microsoft Exchange ServersThe Hacker News·Jun 17, 02:32 UTC · Jun 17, 2022Ransomware57
Almost 2,000 Exchange servers hacked using ProxyShell exploitThe Record·Dec 15, 00:00 UTC · Dec 15, 2022RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
BlackCat Ransomware affiliates target unpatched Microsoft Exchange serversSecurity Affairs·Jun 16, 21:53 UTC · Jun 16, 2022Ransomware57
Play ransomware attacks use a new exploit to bypass ProxyNotShell mitigations on Exchange serversSecurity Affairs·Dec 21, 23:26 UTC · Dec 21, 2022RansomwareCVE-2022-41040CVE-2022-41082CVE-2022-4108060
China-linked hackers target gov agencies by exploiting known flawsSecurity Affairs·Sep 15, 09:16 UTC · Sep 15, 2020RansomwareCVE-2020-5902CVE-2019-19781CVE-2019-11510+1 CVEs60
Concerns as Ransomware and Exchange Server Attacks SurgeInfosecurity Magazine·Mar 30, 11:25 UTC · Mar 30, 2021RansomwareCVE-2021-2706560
Canadian university dealing with ransomware attack on email systemThe Record·Jun 2, 21:01 UTC · Jun 2, 2023Ransomware57
#RSAC: NSA Outlines Threats from Russia, China and RansomwareInfosecurity Magazine·Jun 9, 22:00 UTC · Jun 9, 2022Ransomware57
Head Mare and Twelve: Joint attacks on Russian entitiesKaspersky Securelist·Mar 13, 10:07 UTC · Mar 13, 2025RansomwareCVE-2023-38831CVE-2021-2685560
US authorities have indicted Black Kingdom ransomware adminSecurity Affairs·May 5, 00:15 UTC · May 5, 2025Ransomware57
We\'re responding in election cycles:' Niloofar Razi Howe on the big changes needed to prevent the next SolarWinds attackThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Ransomware57
Quarterly Report: Incident Response trends from Winter 2020Cisco Talos·Mar 24, 12:26 UTC · Mar 24, 2021RansomwareCVE-2021-26855CVE-2020-5902CVE-2019-1893560
Fog ransomware attack on Asia financial org draws attention over use of employee monitoring softwareThe Record·Jun 12, 17:06 UTC · Jun 12, 2025Ransomware57
US, UK, and Australia warn of Iranian hacking activity after Microsoft reportThe Record·Dec 19, 00:00 UTC · Dec 19, 2022RansomwareCVE-2018-13379CVE-2020-12812CVE-2019-5591+1 CVEs60
Ransomware Attack Wipes Out Four Months of Sri Lankan Government DataInfosecurity Magazine·Sep 11, 12:10 UTC · Sep 11, 2023Ransomware57
IKEA hit by a cyber attack that uses stolen internal replySecurity Affairs·Nov 27, 11:27 UTC · Nov 27, 2021RansomwareCVE-2021-26855CVE-2021-34473CVE-2021-3452360
From BlackMatter to BlackCat: Analyzing two attacks from one affiliateCisco Talos·Mar 17, 11:58 UTC · Mar 17, 2022Ransomware57
IT threat evolution in Q3 2021. PC statisticsKaspersky Securelist·Nov 26, 12:00 UTC · Nov 26, 2021RansomwareCVE-2019-7481CVE-2021-1675CVE-2021-34527+4 CVEs60
New Incident Report Reveals How Hive Ransomware Targets OrganizationsThe Hacker News·Apr 21, 10:00 UTC · Apr 21, 2022RansomwareCVE-2021-31207CVE-2021-34523CVE-2021-3447360
Threat actor exploits MS ProxyShell flaws to deploy Babuk ransomwareSecurity Affairs·Nov 5, 11:52 UTC · Nov 5, 2021Ransomware57
Rackspace Hosted Exchange service outage caused by security incidentHelp Net Security·Dec 5, 00:00 UTC · Dec 5, 2022Ransomware57
Epsilon Red – more than 3.5 thousand servers are still vulnerableSecurity Affairs·Jun 26, 05:11 UTC · Jun 26, 2021RansomwareCVE-2020-1472CVE-2021-26855CVE-2021-2706560
FIN7 Cybercrime Syndicate Emerges as a Major Player in Ransomware LandscapeThe Hacker News·Dec 26, 11:59 UTC · Dec 26, 2022RansomwareCVE-2020-0688CVE-2021-4232160
Rackspace ransomware attack was executed by using previously unknown security exploitHelp Net Security·Nov 20, 13:31 UTC · Nov 20, 2023RansomwareCVE-2022-41082CVE-2022-4108060
FBI operation removed web shells from hacked Exchange servers across the USThe Record·Jan 26, 00:00 UTC · Jan 26, 2023Ransomware57
Rackspace Hosted Exchange outage was caused by ransomwareHelp Net Security·Dec 6, 00:00 UTC · Dec 6, 2022Ransomware157