Threat Advisory: HAFNIUM and Microsoft Exchange zeroCisco Talos·Mar 4, 15:58 UTC · Mar 4, 2021Advisory in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+5 CVEs160
Black Kingdom ransomwareKaspersky Securelist·Jun 17, 09:42 UTC · Jun 17, 2021RansomwareCVE-2021-27065CVE-2019-11510CVE-2021-26855+2 CVEs60
Prometei botnet is targeting ProxyLogon Microsoft Exchange flawsSecurity Affairs·Mar 11, 11:58 UTC · Mar 11, 2023MalwareCVE-2021-27065CVE-2021-2685847
Hackers Actively Searching for Unpatched Microsoft Exchange ServersThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2021Vulnerability in the wildCVE-2021-26855CVE-2021-27065CVE-2021-34473+7 CVEs60
Quarterly Report: Incident Response trends from Spring 2021Cisco Talos·Jun 10, 12:00 UTC · Jun 10, 2021RansomwareCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
Defending Microsoft Exchange from encrypted attacks with Cisco Secure IPSCisco Talos·Mar 23, 20:50 UTC · Mar 23, 2021VulnerabilityCVE-2021-26855CVE-2021-2706560
Researchers warn of a surge in cyber attacks against Microsoft ExchangeSecurity Affairs·Mar 12, 22:51 UTC · Mar 12, 2021Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft Exchange Cyber Attack — What Do We Know So Far?The Hacker News·Mar 10, 08:44 UTC · Mar 10, 2021Data breach in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Hafnium Update: Continued Microsoft Exchange Server ExploitationCisco Talos·Mar 10, 00:52 UTC · Mar 10, 2021Exploit / PoC60
Chinese hackers hit thousands of organizations using Microsoft ExchangeSecurity Affairs·Mar 9, 19:09 UTC · Mar 9, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Microsoft updated MSERT to detect web shells used in attacks against Microsoft Exchange installsSecurity Affairs·Mar 8, 13:11 UTC · Mar 8, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Four zero-days in Microsoft Exchange actively exploited in the wildSecurity Affairs·Mar 3, 01:23 UTC · Mar 3, 2021Exploit / PoC in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Suspected Chinese Group Calypso APT Exploiting Vulnerable Microsoft Exchange ServersRecorded Future·Dec 13, 00:00 UTC · Dec 13, 2018Vulnerability in the wildCVE-2021-26855CVE-2021-27065CVE-2021-26857+1 CVEs60
Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via KeyloggersThe Hacker News·Aug 18, 06:29 UTC · Aug 18, 2025Data breachCVE-2014-4078CVE-2020-0796CVE-2021-26855+7 CVEs160
China-Linked Silk Typhoon Expands Cyber Attacks to IT Supply Chains for Initial AccessThe Hacker News·Mar 7, 04:04 UTC · Mar 7, 2025Data breach in the wildCVE-2025-0282CVE-2024-3400CVE-2023-3519+5 CVEs60
Chinese Hackers Use GHOSTSPIDER Malware to Hack Telecoms Across 12+ CountriesThe Hacker News·Nov 28, 09:13 UTC · Nov 28, 2024MalwareCVE-2023-46805CVE-2024-21887CVE-2023-48788+5 CVEs47
Malware linked to Salt Typhoon used to hack telcos around the worldCyberScoop·Nov 26, 02:05 UTC · Nov 26, 2024Malware in the wildCVE-2023-46805CVE-2024-21887CVE-2023-48788+5 CVEs60
14 Million Patients Impacted by US Healthcare Data Breaches in 2024Infosecurity Magazine·Sep 24, 13:45 UTC · Sep 24, 2024Data breachCVE-2021-34473CVE-2021-34523CVE-2021-31207+7 CVEs160
Actor Exploits Microsoft Exchange Server Vulnerabilities, Cortex XDR Blocks Harvesting of CredentialsPalo Alto Unit 42·Jun 6, 13:23 UTC · Jun 6, 2024Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Understanding REvil: REvil Threat Actors May Have Returned (Updated)Palo Alto Unit 42·Jun 5, 20:39 UTC · Jun 5, 2024Threat actor57
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
Top 12 vulnerabilities routinely exploited in 2022Help Net Security·Aug 7, 07:41 UTC · Aug 7, 2023VulnerabilityCVE-2018-13379CVE-2021-34473CVE-2021-31207+23 CVEs147
Microsoft Exchange bugs top list of exploited vulnerabilities affecting financial sectorThe Record·Feb 3, 00:00 UTC · Feb 3, 2023VulnerabilityCVE-2015-1635CVE-2021-31206CVE-2021-34523+5 CVEs60
Microsoft: Chinese APT Targeted Exchange Servers With Four ZeroThe Record·Jan 30, 00:00 UTC · Jan 30, 2023Exploit / PoCCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
German government warns of APT27 activity targeting local companiesThe Record·Jan 17, 00:00 UTC · Jan 17, 2023Threat actorCVE-2021-40539CVE-2021-26855CVE-2021-26857+2 CVEs60
CISA: Multiple government hacking groups had ‘longThe Record·Jan 10, 00:00 UTC · Jan 10, 2023VulnerabilityCVE-2021-26855CVE-2021-26857CVE-2021-26868+1 CVEs60
US, UK, Australia issue joint advisory on today's top exploited vulnerabilitiesThe Record·Dec 12, 00:00 UTC · Dec 12, 2022VulnerabilityCVE-2019-19781CVE-2019-11510CVE-2018-13379+26 CVEs147
FBI, NSA and CISA Warns of Russian Hackers Targeting Critical InfrastructureThe Hacker News·Jan 12, 10:47 UTC · Jan 12, 2022AdvisoryCVE-2018-13379CVE-2019-1653CVE-2019-2725+13 CVEs60
The worst cyber attacks of 2021Security Affairs·Jan 4, 21:18 UTC · Jan 4, 2022Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+5 CVEs60
Microsoft vulnerabilities have grave implications for organizations of all sizesHelp Net Security·Dec 10, 00:00 UTC · Dec 10, 2021VulnerabilityCVE-2021-26855CVE-2021-27065CVE-2021-31196+8 CVEs60
IranSecurity Affairs·Nov 17, 10:08 UTC · Nov 17, 2021RansomwareCVE-2018-13379CVE-2021-26855CVE-2021-26857+2 CVEs160
Microsoft Issues Security Patches for 89 Flaws — IE 0The Hacker News·Aug 13, 09:07 UTC · Aug 13, 2021Vulnerability in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+8 CVEs60
IT threat evolution Q2 2021Kaspersky Securelist·Aug 12, 10:12 UTC · Aug 12, 2021RansomwareCVE-2018-0802CVE-2021-1732CVE-2021-28310+2 CVEs60
Top 30 Critical Security Vulnerabilities Most Exploited by HackersThe Hacker News·Aug 4, 09:03 UTC · Aug 4, 2021Vulnerability in the wildCVE-2019-19781CVE-2019-11510CVE-2018-13379+26 CVEs60
US, UK, and Australian agencies warn of top routinely exploited issuesSecurity Affairs·Jul 28, 20:29 UTC · Jul 28, 2021VulnerabilityCVE-2021-26855CVE-2021-26857CVE-2021-26858+13 CVEs135
Epsilon Red – more than 3.5 thousand servers are still vulnerableSecurity Affairs·Jun 26, 05:11 UTC · Jun 26, 2021RansomwareCVE-2020-1472CVE-2021-26855CVE-2021-2706560
March 2021 Patch Tuesday forecast: Off to an early startHelp Net Security·Jun 8, 18:28 UTC · Jun 8, 2021VulnerabilityCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
IT threat evolution Q1 2021Kaspersky Securelist·May 31, 07:32 UTC · May 31, 2021Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60