/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft confirms two zero-days in Exchange Server 2013, 2016, and 2019 are being exploited in the wild; security firm GTSC suspects a Chinese threat actor

Microsoft has confirmed that two recently reported zero-day vulnerabilities in Microsoft Exchange Server 2013, 2016, and 2019 are being exploited in the wild.

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Exchange had already been a major target: Microsoft previously warned of four actively exploited flaws tied to a Chinese state-sponsored actor, and ESET later reported multiple mostly state-backed groups exploiting Exchange vulnerabilities across thousands of servers. Kaspersky also identified malware used to backdoor Exchange servers at government and military organizations.

The new confirmation places the affected Exchange generations back in an active-exploitation cycle. GTSC's attribution is a suspicion, but the immediate operational fact is Microsoft's confirmation that attackers are using the two flaws in the wild.

First-order effects

  • Organizations running the affected Exchange Server versions must treat exposed servers as potential incident-response cases, rather than merely a routine vulnerability-management task.
  • Microsoft faces renewed pressure from Exchange customers for mitigation guidance as active exploitation broadens the urgency beyond GTSC's initial reporting.

Second-order effects

  • Security teams will prioritize Exchange monitoring and containment ahead of lower-risk patch work, reflecting the damage potential established by the earlier actively exploited Exchange zero-days.
  • The suspected Chinese connection will focus defenders' attention on targeted government and military environments, which related coverage shows have previously been backdoored through Exchange.

Third-order effects

  • Repeated active exploitation makes self-hosted messaging infrastructure a durable concentration point for state-linked intrusion campaigns, increasing the premium on rapid detection and response around widely deployed enterprise software.
  • If exploitation of Exchange continues to recur, enterprise buyers and Microsoft will face stronger incentives to reduce the exposure window between flaw disclosure and defensive action.

The trend: Exchange is becoming a recurring focal point in the broader pattern of state-linked actors weaponizing newly disclosed enterprise-software flaws before defenders can respond.

Discussion

  • @gossithedog Kevin Beaumont on x
    🚨 There's reports emerging that a new zero day exists in Microsoft Exchange, and is being actively exploited in the wild 🚨 I can confirm significant numbers of Exchange servers have been backdoored - including a honeypot. Thread to track issue follows:
  • @blackorbird @blackorbird on x
    Exchange 0day exploit in wild. #APT https://www.gteltsc.vn/... https://twitter.com/...
  • @jeffmcjunkin Jeff McJunkin on x
    🚨 WARNING 🚨 Another day, another 0day exploited in the wild, this time for Exchange. https://gteltsc.vn/... If you have on-prem Exchange port 443 exposed, assume breach. There's no patch, so mitigate in place and search for IOC's. Then... start the migration project.
  • @abuse_ch @abuse_ch on x
    New Exchange #0day exploit in the wild 🔥🔥🔥 English version here 👇👇👇 https://gteltsc.vn/... https://twitter.com/...
  • @certnz @certnz on x
    VULNERABILITY AFFECTING MICROSOFT EXCHANGE We are aware of open source reports of this vulnerability being exploited. We recommend organisations ensure they are running the latest Cumulative Update and Security Update and look into appropriate mitigations: https://gteltsc.vn/...
  • @trendmicrorsrch @trendmicrorsrch on x
    UPDATE: Microsoft has released a blog acknowledging the two zero-days and assigned these CVEs: CVE-2022-41040 and CVE-2022-41082. Mitigations are also discussed, read here: https://msrc-blog.microsoft.com/ ... https://twitter.com/...
  • @tanmayg Tanmay Ganacharya on x
    Microsoft Exchange Online Customers do not need to take any action. On premises Microsoft Exchange customers, follow the blog to review and apply the URL Rewrite Instructions and block exposed Remote PowerShell ports.
  • @arekfurt @arekfurt on x
    “It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either of the two vulnerabilities.” Well that's something at least. Also, read the text here about impacts on Exchange Online closely :) https://msrc-blog.microsof…
  • @arekfurt @arekfurt on x
    Importantly, MS has a mitigation that is effective “at breaking current attack chains” and that should not impact legit functionality. MS is going to patch out of band, and exploitation requires authentication. Still, strongly consider mitigating ASAP. https://msrc-blog.microsoft…
  • @trendmicrorsrch @trendmicrorsrch on x
    Security Alert: Two #zeroday vulnerabilities that were submitted to #Microsoft via @thezdi could allow attackers to perform remote code execution (RCE) on affected Microsoft Exchange servers. For more updates, keep watch here: https://research.trendmicro.com/ 3SKbGFT #0day @Trend…
  • @cglyer Christopher Glyer on x
    Exchange server vuln summary Can be exploited if 1️⃣PowerShell port accessible (5985/5986) 2️⃣User creds required “Microsoft is aware of limited targeted attacks” “working on an accelerated timeline to release a fix” Mitigations & detection guidance 👇 https://msrc-blog.microsoft.…
  • @r00tbsd Paul Rascagnères on x
    Some explanations from MS concerning the Exchange 0d: https://msrc-blog.microsoft.com/ ... The attackers exploited 2 vulns and the first one needs to be authenticated.
  • @gossithedog Kevin Beaumont on x
    Microsoft appear to be aware but have not informed customers.
  • @gossithedog Kevin Beaumont on x
    Microsoft have a blog out. It's two new zero days indeed - however they need authentication. There's no technical info, but it looks like the Proxyshell issues weren't fully fixed. https://msrc-blog.microsoft.com/ ...