Sources: at least 30K US organizations have been hacked by an aggressive Chinese espionage group exploiting unpatched flaws in Microsoft's Exchange Server
At least 30,000 organizations across the United States — including a significant number of small businesses, towns …
Krebs on SecurityBrian Krebs
Context & Ripple Effects
Microsoft had already issued patches for four Exchange zero days tied to a Chinese state-sponsored actor when sources reported broad US compromise. Earlier CISA reporting had also linked China-associated groups to exploitation of Exchange and other enterprise products, making the episode part of a recurring focus on perimeter software.
At least 30,000 US organizations face incident-response work alongside patching, as exploitation of unpatched Exchange servers may have already provided the espionage group access.
Microsoft’s Exchange security response becomes an urgent operational issue for customers that had not deployed the available fixes.
Second-order effects
Organizations running Exchange must treat patch deployment alone as insufficient and investigate whether their servers were compromised before remediation.
The reported US volume and later global exploitation broaden the workload for security teams and incident-response providers beyond the initially identified threat actor.
Third-order effects
The episode reinforces that delayed patching of widely deployed enterprise software can turn a vendor disclosure into a shared exposure across public-sector and small-business users.
If state-backed groups continue to converge on the same disclosed flaws, enterprise email infrastructure will remain a high-leverage target where defensive speed matters as much as vulnerability discovery.
The trend: State-linked cyber operations are increasingly exploiting disclosed flaws in broadly deployed enterprise systems before organizations can complete remediation.
Sources who've briefed U.S. national security advisors say >30K U.S. organizations hacked by newly-found holes in Microsoft's Exchange email products, and that 100s of thousands of victim organizations worldwide now have web-based backdoors installed. https://krebsonsecurity.com/…
Experts interviewed described the cleanup effort required from this attack as “urgent,” “unprecedented” and “Herculean.” From the list of victims I've seen so far, the scope of this attack is fairly staggering. https://twitter.com/...
.@Mandiant Managed Defense observed multiple instances of abuse of Microsoft Exchange Server within at least one client environment. So we built #threathunting campaigns to identify additional Exchange Server abuse. Learn more: https://www.fireeye.com/... https://twitter.com/...
...and not all by APTs Don't flatter yourself. Your small flower shop is getting raided by ransomware gangs, not APT41 & friends https://twitter.com/...
Important to remember that China doesn't want all these targets. Like other recent incidents broad footholds will allow them to select victims that offer the intelligence or access they want most. https://twitter.com/...
Thoughts on the Hafnium Exchange hack: (1) it's going to disproportionately impact those that can least afford it (SMBs, Edu, States, locals), (2) incident response teams are BURNED OUT & this is at a really bad time, (3) few orgs should be running exchange servers these days. ht…
That sucks for a lot of IT and sysadmins out there this weekend, especially the ones that didn't patch (patching Exchange servers on patch Tuesday usually doesn't happen to having to test the patches out first or roll out at a time of their choosing). Hits bigly. https://twitter.…
Some 30,000 US entities have been hacked through the four Exchange server vulns that Microsoft patched this wk - the vulns allow hackers to steal email from victims. Victims include “a significant number of small businesses, towns, cities and local govs” https://twitter.com/...
This is why you should never send sensitive info via email. Attach files using Dropbox or Drive and remove when they've been received. https://krebsonsecurity.com/ ...
Earlier this week, @Microsoft shared #zeroday vulnerabilities used to attack on-prem versions of Microsoft Exchange Server. Managed Defense found multiple instances of abuse in at least one client environment starting in Jan. 2021. ▶️ Get the details: https://www.fireeye.com/... …
Regarding recent exchange zero-days: FireEye says that based on their telemetry, they have identified “an array of affected victims including US-based retailers, local governments, a university, and an engineering firm” https://www.fireeye.com/... https://twitter.com/...
New blog alert by @anthomsec, @_bromiley, and co. on the Microsoft Exchange Zero-Days. Details on web shells seen, investigation tips, and IOCs with Last Know True timestamps. 👀https://www.fireeye.com/ ...
Microsoft today released emergency updates to plug 4 security holes in Exchange Server 2013-19. Microsoft and others say a previously unidentified Chinese cyber espionage group is using the flaws to plunder email communications at targeted organizations. https://krebsonsecurity.c…