/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft confirms two zero-days in Exchange Server 2013, 2016, and 2019 are being exploited in the wild; security firm GTSC suspects a Chinese threat actor

Microsoft has confirmed that two recently reported zero-day vulnerabilities in Microsoft Exchange Server 2013, 2016, and 2019 are being exploited in the wild.

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Microsoft Exchange had already been a repeated target: Microsoft previously warned of a Chinese state-sponsored campaign exploiting four undisclosed Exchange flaws, and ESET later reported exploitation by at least ten mostly state-backed groups across thousands of servers. Kaspersky also identified malware used to backdoor Exchange servers at government and military organizations.

The new confirmation puts the affected 2013, 2016, and 2019 deployments back into an active-incident posture, while GTSC's suspected Chinese attribution connects the event to the earlier pattern of state-linked Exchange targeting.

First-order effects

  • Organizations running the named Exchange Server versions face active exploitation risk now, requiring their security teams to prioritize containment and remediation over routine patch scheduling.
  • Microsoft must respond to an in-the-wild incident across three supported Exchange generations, while GTSC's attribution assessment concentrates attention on a suspected Chinese threat actor.

Second-order effects

  • Security teams are likely to give Exchange exposure priority over less immediately exploited vulnerabilities, particularly after the earlier multi-group exploitation of Exchange weaknesses showed how quickly campaigns can broaden.
  • Government and military Exchange operators draw added scrutiny because prior reporting identified backdoors on servers in those sectors, increasing the value of rapid incident review alongside remediation.

Third-order effects

  • Repeated exploitation of Exchange flaws by state-linked groups points to enterprise mail infrastructure as a durable high-value target, making legacy server exposure a continuing security-management issue rather than a one-off vulnerability event.
  • If this pattern persists, vendors and customers will be judged increasingly on how quickly they detect and contain active exploitation across installed server generations.

The trend: Enterprise messaging servers are becoming a recurring focus of state-linked intrusion campaigns, with active-exploitation alerts driving faster defensive response cycles.

Discussion

  • @gossithedog Kevin Beaumont on x
    🚨 There's reports emerging that a new zero day exists in Microsoft Exchange, and is being actively exploited in the wild 🚨 I can confirm significant numbers of Exchange servers have been backdoored - including a honeypot. Thread to track issue follows:
  • @blackorbird @blackorbird on x
    Exchange 0day exploit in wild. #APT https://www.gteltsc.vn/... https://twitter.com/...
  • @jeffmcjunkin Jeff McJunkin on x
    🚨 WARNING 🚨 Another day, another 0day exploited in the wild, this time for Exchange. https://gteltsc.vn/... If you have on-prem Exchange port 443 exposed, assume breach. There's no patch, so mitigate in place and search for IOC's. Then... start the migration project.
  • @abuse_ch @abuse_ch on x
    New Exchange #0day exploit in the wild 🔥🔥🔥 English version here 👇👇👇 https://gteltsc.vn/... https://twitter.com/...
  • @certnz @certnz on x
    VULNERABILITY AFFECTING MICROSOFT EXCHANGE We are aware of open source reports of this vulnerability being exploited. We recommend organisations ensure they are running the latest Cumulative Update and Security Update and look into appropriate mitigations: https://gteltsc.vn/...
  • @trendmicrorsrch @trendmicrorsrch on x
    UPDATE: Microsoft has released a blog acknowledging the two zero-days and assigned these CVEs: CVE-2022-41040 and CVE-2022-41082. Mitigations are also discussed, read here: https://msrc-blog.microsoft.com/ ... https://twitter.com/...
  • @tanmayg Tanmay Ganacharya on x
    Microsoft Exchange Online Customers do not need to take any action. On premises Microsoft Exchange customers, follow the blog to review and apply the URL Rewrite Instructions and block exposed Remote PowerShell ports.
  • @arekfurt @arekfurt on x
    “It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either of the two vulnerabilities.” Well that's something at least. Also, read the text here about impacts on Exchange Online closely :) https://msrc-blog.microsof…
  • @arekfurt @arekfurt on x
    Importantly, MS has a mitigation that is effective “at breaking current attack chains” and that should not impact legit functionality. MS is going to patch out of band, and exploitation requires authentication. Still, strongly consider mitigating ASAP. https://msrc-blog.microsoft…
  • @trendmicrorsrch @trendmicrorsrch on x
    Security Alert: Two #zeroday vulnerabilities that were submitted to #Microsoft via @thezdi could allow attackers to perform remote code execution (RCE) on affected Microsoft Exchange servers. For more updates, keep watch here: https://research.trendmicro.com/ 3SKbGFT #0day @Trend…
  • @cglyer Christopher Glyer on x
    Exchange server vuln summary Can be exploited if 1️⃣PowerShell port accessible (5985/5986) 2️⃣User creds required “Microsoft is aware of limited targeted attacks” “working on an accelerated timeline to release a fix” Mitigations & detection guidance 👇 https://msrc-blog.microsoft.…
  • @r00tbsd Paul Rascagnères on x
    Some explanations from MS concerning the Exchange 0d: https://msrc-blog.microsoft.com/ ... The attackers exploited 2 vulns and the first one needs to be authenticated.
  • @gossithedog Kevin Beaumont on x
    Microsoft appear to be aware but have not informed customers.
  • @gossithedog Kevin Beaumont on x
    Microsoft have a blog out. It's two new zero days indeed - however they need authentication. There's no technical info, but it looks like the Proxyshell issues weren't fully fixed. https://msrc-blog.microsoft.com/ ...
  • @gossithedog Kevin Beaumont on x
    Microsoft have quietly deleted the guidance about blocking WinRM/PowerShell Remoting ports from their guidance. It was wrong. https://msrc-blog.microsoft.com/ ...
  • @gossithedog Kevin Beaumont on x
    For the record this is the section Microsoft removed from the ProxyNotShell blog, and didn't document they had removed it. If you made firewall changes to prevent RCE, it didn't work. https://web.archive.org/... https://twitter.com/...
  • @briankrebs @briankrebs on x
    Microsoft has released mitigation advice for Exchange Server users regarding exploits on 2 new 0-day Exchange bugs. The attack requires authentication, but experts warn the China-based hacking group apparently involved is also phishing Exchange passwords https://krebsonsecurity.c…
  • @swiftonsecurity @swiftonsecurity on x
    Note regardless of the situation, if you have on-prem Exchange you should be preparing by getting it up-to-date and in a good healthy situation, right now. https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    MS have issued two new CVEs overnight. The path for #ProxyNotShell is strikingly similar to ProxyShell, same as vuln classes. The detections from 2021 I wrote in the blog still work for ProxyNotShell. https://doublepulsar.com/...