Hi everyone!
I hope you all had a great week. This is a pretty packed issue, again. Honestly, when I started the newsletter years ago I feared that I wouldn't have enough content to fill out an issue each week. Now it's all about finding a balance between keeping things somewhat brief but not miss anything interesting. Please let me know if I'm not striking that balance properly. In the meanwhile, I hope you get value out of this one.
Cheers!
Dieter
This is a big one, but I'll try to summarize. A previously unknown Chinese hacker group has been attacking Microsoft Exchange servers with zero-days. They get inside, steal e-mails and open up web shells to compromise the networks further.
Since Microsoft has gone public this week the hacker group has massively ramped up their attack, compromising thousands of servers per hour, globally. The total count of compromised networks seems to be in the hundreds of thousands.
If you run Exchange servers you are told to assume compromise, even going back as far as September 2020. There are patches, indicators of compromise, tools to find the installed webshells, and a lot more info to dig in to.
The linked article breaks the initial news and links to the four zero-day CVE's. Some more info:
- The attacks seem to be getting the name "ProxyLogon", just fyi.
- Great follow-up article from Krebs: link.
- CISA issues emergency directives: link.
- Patches might seem installed but not fix anything, double check: link.
- Guidance by Microsoft on removing webshells: link.