/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Microsoft took nearly two months to issue a patch after hearing of Exchange Server's flaws, even as a mass-hack unfolded; some of the flaws were 10+ years old

Krebs on Security Brian Krebs

Context & Ripple Effects

The Exchange episode followed a separate Microsoft patch for a critical Windows and Server flaw that had reportedly remained in code for 17 years, underscoring how long-lived defects can surface across widely deployed enterprise software. Here, the urgency was compounded by active compromise before a fix was available.

The scope became clearer days later when ESET reported at least ten mostly state-backed groups exploiting the Exchange flaws across thousands of servers. Microsoft’s subsequent April patch batch also included four NSA-discovered critical Exchange flaws, keeping Exchange remediation at the center of its security response.

First-order effects

  • Exchange Server customers were left to defend systems during an active mass hack until Microsoft released patches for flaws it had known about for nearly two months.
  • Microsoft faced an immediate remediation burden spanning both the exploited vulnerabilities and additional critical Exchange issues addressed in its next patch cycle.

Second-order effects

  • The reported breadth of exploitation turned patch deployment into an incident-response task for Exchange administrators, rather than a routine maintenance update.
  • The episode put Microsoft’s vulnerability-response cadence under sharper scrutiny, a concern echoed later when critics said a critical Azure RCE took several months and three patches to resolve.

Third-order effects

  • Long-lived flaws in enterprise infrastructure make vendor patch speed a core part of customer risk: a delayed fix can leave broadly deployed systems exposed while attackers scale exploitation.
  • If Exchange-style incidents recur, enterprise buyers are likely to place greater weight on vendors’ disclosure, mitigation, and patch-delivery practices alongside the software’s feature set.

The trend: Enterprise security risk is increasingly shaped by the combination of aging code bases, widely deployed server software, and the speed at which vendors turn vulnerability reports into usable fixes.

Discussion

  • @fxshaw Frank X. Shaw on x
    Microsoft engineers worked around the clock to deliver fixes tonight for older (and unsupported) cumulative update versions of Windows Exchange. This is just part of the tools and guidance we shared with customers tonight: https://techcommunity.microsoft.com/ ...
  • @brianweeden @brianweeden on x
    This is why cyber is hard - vulnerabilities can lurk for years, you can't force everyone to pay to be on the latest version, and it takes time to patch https://krebsonsecurity.com/ ... https://twitter.com/...
  • @jaredctate @jaredctate on x
    The Zero Day exploit in #Microsoft #ExchangeServer hack had been in the code for at least 10 years. Here is a great time line article by @briankrebs. The fall out from this could be the worst hack in history. It will most definetly ramp up geo tensions. https://krebsonsecurity.co…
  • @epro Emil Protalinski on x
    First the SolarWinds hack, and now this. Long before Microsoft doubled down on the cloud, it was making impressive gains in security. I'm starting to wonder if Microcloud has become complacent in security. https://twitter.com/...
  • @briankrebs @briankrebs on x
    1/2: Today's timeline showing Microsoft took nearly 2 months to alert its customers about increasingly active attacks on 4 zero-day flaws in Exchange brings up a key question: Is it okay to wait that long to alert customers, let alone patch? https://krebsonsecurity.com/ ...
  • @campuscodi Catalin Cimpanu on x
    @Techmeme @briankrebs That's actually super normal for most bug bounty programs, especially for big corps like MSFT that have to test release builds across tens of products. The patching timeline is a non-issue, especially since MSFT rushed out patches when it learned it was gett…
  • @briankrebs @briankrebs on x
    When did Microsoft first learn about the Exchange server flaws? Jan. 5. Today's timeline lays out the 2-month interval between initial attack reports to Microsoft and mass-exploitation that left hundreds of thousands of organizations with backdoor trojans. https://krebsonsecurity…
  • @joetidy Joe Tidy on x
    European Banking Authority hit by Microsoft Exchange hack. The EU body said personal data may have been accessed from its servers. And it had pulled its entire email system offline while it assessed the damage. https://www.bbc.co.uk/...