Ursnif campaign targets Italy with a new infection ChainSecurity Affairs·Mar 17, 15:03 UTC · Mar 17, 2020Threat actor45
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Lemon Duck spreads its wings: Actors target Microsoft Exchange servers, incorporate new TTPsCisco Talos·May 7, 19:50 UTC · May 7, 2021Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs160
Server-side attacks, C&C in public clouds and other MDR cases we observedKaspersky Securelist·Nov 2, 08:00 UTC · Nov 2, 2022Vulnerability30
Microsoft updated MSERT to detect web shells used in attacks against Microsoft Exchange installsSecurity Affairs·Mar 8, 13:11 UTC · Mar 8, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange ServersRecorded Future·Dec 13, 00:00 UTC · Dec 13, 2018Vulnerability in the wildCVE-2021-26855CVE-2021-27065CVE-2021-26857+1 CVEs60
ToddyCat: Keep calm and check logsKaspersky Securelist·Oct 12, 10:41 UTC · Oct 12, 2023Vulnerability42
Threat Advisory: Microsoft warns of actively exploited vulnerabilities in Exchange ServerCisco Talos·Sep 30, 21:16 UTC · Sep 30, 2022Vulnerability in the wildCVE-2022-41040CVE-2022-4108260