Security News > 2021 > March > As attacks on Exchange servers escalate, Microsoft investigates potential PoC exploit leak
Microsoft Exchange servers around the world are still getting compromised via the ProxyLogon and three other vulnerabilities patched by Microsoft in early March.
A. Human operated ransomware attacks are utilizing the Microsoft Exchange vulnerabilities to exploit customers.
The source of the Microsoft Exchange exploit still unknown.
Microsoft is reportedly investigating whether those who created the exploit might have obtained a "Proof of concept" attack code that the company distributed on February 23 to 80 or so security partners through its Microsoft Active Protections Program.
Microsoft Security Team says that on-premises Exchange servers are most often used by small and medium-sized businesses, "Although larger organizations with on-premises Exchange servers have also been affected."
Microsoft has released Exchange On-Premises Mitigation Tool, which quickly performs the initial steps for mitigating the ProxyLogon flaw on any Exchange server and attempts to remediate found compromises.
News URL
http://feedproxy.google.com/~r/HelpNetSecurity/~3/tLAkZ4lHpTk/
Related news
- Exploit released for new Windows Server "WinReg" NTLM Relay attack (source)
- VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware (source)
- Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks (source)
- Week in review: Windows Server 2025 gets hotpatching option, PoC for SolarWinds WHD flaw released (source)
- Alert: Adobe Commerce and Magento Stores Under Attack from CosmicSting Exploit (source)
- Critical Ivanti RCE flaw with public exploit now used in attacks (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- Google Adds New Pixel Security Features to Block 2G Exploits and Baseband Attacks (source)
- Microsoft and DOJ disrupt Russian FSB hackers' attack infrastructure (source)
- Microsoft fixes Remote Desktop issues caused by Windows Server update (source)