New LockFile gang uses ProxyShell and PetitPotam exploitsSecurity Affairs·Aug 23, 20:02 UTC · Aug 23, 2021RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
GhostContainer backdoor for Exchange serversKaspersky Securelist·Jul 17, 08:00 UTC · Jul 17, 2025MalwareCVE-2020-068847
Threat actors are probing Microsoft Exchange servers for ProxyShell flawsSecurity Affairs·Aug 9, 06:55 UTC · Aug 9, 2021Threat actorCVE-2021-34473CVE-2021-34523CVE-2021-3120760
xHunt hackers hit Microsoft Exchange with two news backdoorsSecurity Affairs·Nov 9, 19:17 UTC · Nov 9, 2020Malware42
Microsoft Exchange servers targeted by second ransomware groupThe Record·Nov 17, 00:00 UTC · Nov 17, 2022Ransomware57
Microsoft Exchange servers compromised by Turla APTHelp Net Security·Jul 20, 00:00 UTC · Jul 20, 2023Threat actor57
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
MS Exchange Server Flaws Exploited to Deploy Keylogger in Targeted AttacksThe Hacker News·May 22, 13:43 UTC · May 22, 2024Data breachCVE-2021-34473CVE-2021-34523CVE-2021-3120760
New Toddycat APT Targets MS Exchange Servers in Europe and AsiaInfosecurity Magazine·Jun 21, 17:30 UTC · Jun 21, 2022Vulnerability55
Microsoft Patches Four More Critical Exchange Server BugsInfosecurity Magazine·Apr 14, 10:30 UTC · Apr 14, 2021Vulnerability in the wildCVE-2021-28310CVE-2021-28480CVE-2021-28481+3 CVEs60
Victims of Microsoft Exchange Server zeroCyberScoop·Mar 5, 15:14 UTC · Mar 5, 2021Exploit / PoC in the wild60
Week in review: Exchange Servers under attack, disinformation economics, Patch Tuesday forecastHelp Net Security·Mar 7, 00:00 UTC · Mar 7, 2021Vulnerability in the wildCVE-2021-22681CVE-2021-2670860
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilitiesCisco Talos·Nov 8, 18:22 UTC · Nov 8, 2022Vulnerability in the wildCVE-2022-41039CVE-2022-41044CVE-2022-41088+9 CVEs60
Microsoft Exchange admins advised to expand antivirus scanningHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2023Exploit / PoC60
ProxyToken vulnerability can modify Exchange server configsThe Record·Dec 15, 00:00 UTC · Dec 15, 2022VulnerabilityCVE-2021-3376660
Expert released PoC code for Microsoft Exchange CVE-2021Security Affairs·Nov 23, 17:14 UTC · Nov 23, 2021Exploit / PoC in the wildCVE-2021-4232160
German cyber agency warns 17,000 Microsoft Exchange servers are vulnerable to critical bugsThe Record·Mar 27, 17:02 UTC · Mar 27, 2024Ransomware in the wild60
New PowerExchange Backdoor Used in Iranian Cyber Attack on UAE GovernmentThe Hacker News·May 25, 13:39 UTC · May 25, 2023Malware42
Microsoft releases one-click Exchange On-Premises Mitigation ToolHelp Net Security·Mar 16, 00:00 UTC · Mar 16, 2021VulnerabilityCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs35
LightNeuron, a Turla's backdoor used to compromise exchange mail serversSecurity Affairs·May 7, 21:19 UTC · May 7, 2019Malware42
New ToddyCat Hacker Group on Experts' Radar After Targeting MS Exchange ServersThe Hacker News·Jun 23, 10:34 UTC · Jun 23, 2022Malware55
CISA, Microsoft warn of critical Exchange hybrid flaw CVE-2025Security Affairs·Aug 7, 14:05 UTC · Aug 7, 2025Exploit / PoC in the wildCVE-2025-5378660
Microsoft Patch Tuesday updates fix 6 actively exploited zeroSecurity Affairs·Nov 9, 11:54 UTC · Nov 9, 2022Vulnerability in the wildCVE-2022-41028CVE-2022-41040CVE-2022-41128+4 CVEs60
New 'SessionManager' Backdoor Targeting Microsoft Exchange Servers WorldwideInfosecurity Magazine·Jul 1, 17:30 UTC · Jul 1, 2022Malware42
As firms race to patch Microsoft Exchange flaws, security pros brace for ransomware outbreakCyberScoop·Mar 12, 19:28 UTC · Mar 12, 2021Ransomware in the wild60
NCSC: Install Latest Microsoft Exchange Server Updates UrgentlyInfosecurity Magazine·Mar 12, 16:35 UTC · Mar 12, 2021Ransomware60
Hackers compromised the Microsoft Exchange servers at EBASecurity Affairs·Mar 8, 15:17 UTC · Mar 8, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
U.S. CISA adds Adobe, Fortinet, Microsoft Windows, Microsoft Exchange Server flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 14, 07:38 UTC · Apr 14, 2026Exploit / PoC in the wildCVE-2026-34621CVE-2012-1854CVE-2020-9715+4 CVEs260
Max-severity Exchange server flaw under active exploitation by Kremlin hackersArs Technica · Security·Jul 30, 20:57 UTC · Jul 30, 2026Exploit / PoC in the wildCVE-2026-4289760
New 'post-exploitation' threat deployed on Microsoft Exchange servers is spotted by researchersThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Malware30
29,000 Servers Remain Unpatched Against Microsoft Exchange FlawInfosecurity Magazine·Aug 12, 16:00 UTC · Aug 12, 2025Vulnerability in the wildCVE-2025-5378660
Week in review: Attackers probing for vulnerable Exchange servers, RSA Conference 2020 coverageHelp Net Security·Mar 1, 00:00 UTC · Mar 1, 2020Ransomware in the wildCVE-2020-0688CVE-2020-6418CVE-2019-1512660
Hackers Deploy IceApple Exploitation Framework on Hacked MS Exchange ServersThe Hacker News·May 12, 05:36 UTC · May 12, 2022Vulnerability55
Week in review: Backdoor found in XZ utilities, weaponized iMessages, Exchange servers at riskHelp Net Security·Mar 31, 00:00 UTC · Mar 31, 2024Malware in the wildCVE-2024-3094CVE-2023-48022CVE-2023-2495560
Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploitedHelp Net Security·May 17, 00:00 UTC · May 17, 2026Vulnerability in the wildCVE-2026-44413CVE-2026-41940CVE-2026-46300+2 CVEs160
Unpatched Microsoft Exchange Servers hit with cryptojackingCyberScoop·Apr 14, 15:47 UTC · Apr 14, 2021Vulnerability in the wild60
Hackers Hijack Email Reply Chains on Unpatched Exchange Servers to Spread MalwareThe Hacker News·Mar 28, 14:45 UTC · Mar 28, 2022Vulnerability42
Chinese cyberspies used a new PlugX variant, dubbed THOR, in attacks against MS Exchange ServersSecurity Affairs·Jul 28, 16:18 UTC · Jul 28, 2021Vulnerability42