/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: at least 30K US organizations have been hacked by an aggressive Chinese espionage group exploiting unpatched flaws in Microsoft's Exchange Server

At least 30,000 organizations across the United States — including a significant number of small businesses, towns …

Krebs on Security Brian Krebs

Context & Ripple Effects

Microsoft had already issued patches for four Exchange zero days tied to a Chinese state-sponsored actor when sources reported broad US compromise. Earlier CISA reporting had also linked China-associated groups to exploitation of Exchange and other enterprise products, making the episode part of a recurring focus on perimeter software.

The story’s scale matters because the affected population extends beyond large institutions to smaller organizations and towns. Subsequent reporting that multiple mostly state-backed groups were exploiting the same vulnerabilities globally indicates the flaws became a widely used access route rather than a contained campaign.

First-order effects

  • At least 30,000 US organizations face incident-response work alongside patching, as exploitation of unpatched Exchange servers may have already provided the espionage group access.
  • Microsoft’s Exchange security response becomes an urgent operational issue for customers that had not deployed the available fixes.

Second-order effects

  • Organizations running Exchange must treat patch deployment alone as insufficient and investigate whether their servers were compromised before remediation.
  • The reported US volume and later global exploitation broaden the workload for security teams and incident-response providers beyond the initially identified threat actor.

Third-order effects

  • The episode reinforces that delayed patching of widely deployed enterprise software can turn a vendor disclosure into a shared exposure across public-sector and small-business users.
  • If state-backed groups continue to converge on the same disclosed flaws, enterprise email infrastructure will remain a high-leverage target where defensive speed matters as much as vulnerability discovery.

The trend: State-linked cyber operations are increasingly exploiting disclosed flaws in broadly deployed enterprise systems before organizations can complete remediation.

Discussion

  • @briankrebs @briankrebs on x
    Sources who've briefed U.S. national security advisors say >30K U.S. organizations hacked by newly-found holes in Microsoft's Exchange email products, and that 100s of thousands of victim organizations worldwide now have web-based backdoors installed. https://krebsonsecurity.com/…
  • @briankrebs @briankrebs on x
    Experts interviewed described the cleanup effort required from this attack as “urgent,” “unprecedented” and “Herculean.” From the list of victims I've seen so far, the scope of this attack is fairly staggering. https://twitter.com/...
  • @malwaretechblog @malwaretechblog on x
    Working in cybersecurity this past year https://twitter.com/... https://twitter.com/...
  • @jason @jason on x
    We need to take a stronger stance against the CCP's hacking activity & human rights record https://krebsonsecurity.com/ ...
  • @fireeye @fireeye on x
    .@Mandiant Managed Defense observed multiple instances of abuse of Microsoft Exchange Server within at least one client environment. So we built #threathunting campaigns to identify additional Exchange Server abuse. Learn more: https://www.fireeye.com/... https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    ...and not all by APTs Don't flatter yourself. Your small flower shop is getting raided by ransomware gangs, not APT41 & friends https://twitter.com/...
  • @evacide Eva on x
    Meanwhile, back at infosec, everyone who runs an Exchange server is having a very bad day: https://www.wired.com/...
  • @johnhultquist John Hultquist on x
    Important to remember that China doesn't want all these targets. Like other recent incidents broad footholds will allow them to select victims that offer the intelligence or access they want most. https://twitter.com/...
  • @danlinden Dan Linden on x
    Well, this sounds pretty bad. https://twitter.com/...
  • @c_c_krebs Chris Krebs on x
    Thoughts on the Hafnium Exchange hack: (1) it's going to disproportionately impact those that can least afford it (SMBs, Edu, States, locals), (2) incident response teams are BURNED OUT & this is at a really bad time, (3) few orgs should be running exchange servers these days. ht…
  • @sogonsec Chris Humphries on x
    That sucks for a lot of IT and sysadmins out there this weekend, especially the ones that didn't patch (patching Exchange servers on patch Tuesday usually doesn't happen to having to test the patches out first or roll out at a time of their choosing). Hits bigly. https://twitter.…
  • @kimzetter Kim Zetter on x
    Some 30,000 US entities have been hacked through the four Exchange server vulns that Microsoft patched this wk - the vulns allow hackers to steal email from victims. Victims include “a significant number of small businesses, towns, cities and local govs” https://twitter.com/...
  • @artemr Artem Russakovskii on x
    This is why you should never send sensitive info via email. Attach files using Dropbox or Drive and remove when they've been received. https://krebsonsecurity.com/ ...
  • @mandiant @mandiant on x
    Earlier this week, @Microsoft shared #zeroday vulnerabilities used to attack on-prem versions of Microsoft Exchange Server. Managed Defense found multiple instances of abuse in at least one client environment starting in Jan. 2021. ▶️ Get the details: https://www.fireeye.com/... …
  • @campuscodi Catalin Cimpanu on x
    Regarding recent exchange zero-days: FireEye says that based on their telemetry, they have identified “an array of affected victims including US-based retailers, local governments, a university, and an engineering firm” https://www.fireeye.com/... https://twitter.com/...
  • @iamshley_a Iamshley.A on x
    New blog alert by @anthomsec, @_bromiley, and co. on the Microsoft Exchange Zero-Days. Details on web shells seen, investigation tips, and IOCs with Last Know True timestamps. 👀https://www.fireeye.com/ ...
  • @brianmfloyd Brian Floyd on x
    So basically everything has been hacked at this point https://www.wired.com/...
  • @briankrebs @briankrebs on x
    Microsoft today released emergency updates to plug 4 security holes in Exchange Server 2013-19. Microsoft and others say a previously unidentified Chinese cyber espionage group is using the flaws to plunder email communications at targeted organizations. https://krebsonsecurity.c…