home.social

#proxynotshell — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #proxynotshell, aggregated by home.social.

fetched live
  1. China-linked hackers exploit Microsoft Exchange in Azerbaijani energy firm attacks.

    A group of China-linked hackers, known as FamousSparrow, launched a sustained cyberattack on an Azerbaijani oil and gas company, exploiting Microsoft Exchange vulnerabilities in a multi-wave intrusion that spanned three months. The attackers used the ProxyNotShell exploit to gain and maintain access to…

    osintsights.com/china-linked-h

    #ChinalinkedHackers #MicrosoftExchange #Proxynotshell #Famoussparrow #EarthEstries

  2. Later today, the UK government plan to link the Microsoft Exchange #ProxyNotShell incident at the Electoral Commission to China. doublepulsar.com/uk-electoral-

    Edit: I should say, they might have got caught up in ProxyShell too.

  3. Later today, the UK government plan to link the Microsoft Exchange #ProxyNotShell incident at the Electoral Commission to China. doublepulsar.com/uk-electoral-

    Edit: I should say, they might have got caught up in ProxyShell too.

  4. Later today, the UK government plan to link the Microsoft Exchange #ProxyNotShell incident at the Electoral Commission to China. doublepulsar.com/uk-electoral-

    Edit: I should say, they might have got caught up in ProxyShell too.

  5. Later today, the UK government plan to link the Microsoft Exchange #ProxyNotShell incident at the Electoral Commission to China. doublepulsar.com/uk-electoral-

    Edit: I should say, they might have got caught up in ProxyShell too.

  6. Later today, the UK government plan to link the Microsoft Exchange #ProxyNotShell incident at the Electoral Commission to China. doublepulsar.com/uk-electoral-

    Edit: I should say, they might have got caught up in ProxyShell too.

  7. #ProxyNotShell in Exchange Server fingered in UK Electoral Commission hack.

    TechCrunch found Electoral Commission were using on prem Exchange.

    I had a look via @shodan history feature - their Exchange Server, with OWA enabled, was online until later in 2022 (when the incident began) - and didn't have ProxyNotShell patches installed, as Microsoft hadn't released them.

    The mitigations MS released were bypassable, as seen in the Rackspace Hosted Exchange hack.

    techcrunch.com/2023/08/09/pars

  8. #ProxyNotShell in Exchange Server fingered in UK Electoral Commission hack.

    TechCrunch found Electoral Commission were using on prem Exchange.

    I had a look via @shodan history feature - their Exchange Server, with OWA enabled, was online until later in 2022 (when the incident began) - and didn't have ProxyNotShell patches installed, as Microsoft hadn't released them.

    The mitigations MS released were bypassable, as seen in the Rackspace Hosted Exchange hack.

    techcrunch.com/2023/08/09/pars

  9. #ProxyNotShell in Exchange Server fingered in UK Electoral Commission hack.

    TechCrunch found Electoral Commission were using on prem Exchange.

    I had a look via @shodan history feature - their Exchange Server, with OWA enabled, was online until later in 2022 (when the incident began) - and didn't have ProxyNotShell patches installed, as Microsoft hadn't released them.

    The mitigations MS released were bypassable, as seen in the Rackspace Hosted Exchange hack.

    techcrunch.com/2023/08/09/pars

  10. #ProxyNotShell in Exchange Server fingered in UK Electoral Commission hack.

    TechCrunch found Electoral Commission were using on prem Exchange.

    I had a look via @shodan history feature - their Exchange Server, with OWA enabled, was online until later in 2022 (when the incident began) - and didn't have ProxyNotShell patches installed, as Microsoft hadn't released them.

    The mitigations MS released were bypassable, as seen in the Rackspace Hosted Exchange hack.

    techcrunch.com/2023/08/09/pars

  11. #ProxyNotShell in Exchange Server fingered in UK Electoral Commission hack.

    TechCrunch found Electoral Commission were using on prem Exchange.

    I had a look via @shodan history feature - their Exchange Server, with OWA enabled, was online until later in 2022 (when the incident began) - and didn't have ProxyNotShell patches installed, as Microsoft hadn't released them.

    The mitigations MS released were bypassable, as seen in the Rackspace Hosted Exchange hack.

    techcrunch.com/2023/08/09/pars

  12. On Dec 22, 2022, Unit42 released a threat brief on the new OWASSRF exploit method for Microsoft Exchange Server published by CrowdStrike

    Threat Brief: OWASSRF Vulnerability Exploitation

    unit42.paloaltonetworks.com/th

    #OWASSRF #ProxyNotShell #Cybersecurity #CyberThreatIntelligence

  13. On Dec 22, 2022, Unit42 released a threat brief on the new OWASSRF exploit method for Microsoft Exchange Server published by CrowdStrike

    Threat Brief: OWASSRF Vulnerability Exploitation

    unit42.paloaltonetworks.com/th

    #OWASSRF #ProxyNotShell #Cybersecurity #CyberThreatIntelligence

  14. On Dec 22, 2022, Unit42 released a threat brief on the new OWASSRF exploit method for Microsoft Exchange Server published by CrowdStrike

    Threat Brief: OWASSRF Vulnerability Exploitation

    unit42.paloaltonetworks.com/th

    #OWASSRF #ProxyNotShell #Cybersecurity #CyberThreatIntelligence

  15. Wie die #HAW #Hamburg geransomwared wurde? Vielleicht so:

    haw-mailer.haw-hamburg.de (15.11.2022)

    Found Exchange server:
    Build: 15.1.2507.13
    Version: 2016CU23+KB5019077
    Build date: 10/2022
    Affected by CVE-2022-41040
    Affected by CVE-2022-41082
    Affected by CVE-2022-41078
    Affected by CVE-2022-41123
    Affected by CVE-2022-41079
    Affected by CVE-2022-41080

    [via @leakix] #OWASSRF #ProxyNotShell

  16. Wie die #HAW #Hamburg geransomwared wurde? Vielleicht so:

    haw-mailer.haw-hamburg.de (15.11.2022)

    Found Exchange server:
    Build: 15.1.2507.13
    Version: 2016CU23+KB5019077
    Build date: 10/2022
    Affected by CVE-2022-41040
    Affected by CVE-2022-41082
    Affected by CVE-2022-41078
    Affected by CVE-2022-41123
    Affected by CVE-2022-41079
    Affected by CVE-2022-41080

    [via @leakix] #OWASSRF #ProxyNotShell

  17. Wie die #HAW #Hamburg geransomwared wurde? Vielleicht so:

    haw-mailer.haw-hamburg.de (15.11.2022)

    Found Exchange server:
    Build: 15.1.2507.13
    Version: 2016CU23+KB5019077
    Build date: 10/2022
    Affected by CVE-2022-41040
    Affected by CVE-2022-41082
    Affected by CVE-2022-41078
    Affected by CVE-2022-41123
    Affected by CVE-2022-41079
    Affected by CVE-2022-41080

    [via @leakix] #OWASSRF #ProxyNotShell

  18. Wie die #HAW #Hamburg geransomwared wurde? Vielleicht so:

    haw-mailer.haw-hamburg.de (15.11.2022)

    Found Exchange server:
    Build: 15.1.2507.13
    Version: 2016CU23+KB5019077
    Build date: 10/2022
    Affected by CVE-2022-41040
    Affected by CVE-2022-41082
    Affected by CVE-2022-41078
    Affected by CVE-2022-41123
    Affected by CVE-2022-41079
    Affected by CVE-2022-41080

    [via @leakix] #OWASSRF #ProxyNotShell

  19. Wie die #HAW #Hamburg geransomwared wurde? Vielleicht so:

    haw-mailer.haw-hamburg.de (15.11.2022)

    Found Exchange server:
    Build: 15.1.2507.13
    Version: 2016CU23+KB5019077
    Build date: 10/2022
    Affected by CVE-2022-41040
    Affected by CVE-2022-41082
    Affected by CVE-2022-41078
    Affected by CVE-2022-41123
    Affected by CVE-2022-41079
    Affected by CVE-2022-41080

    [via @leakix] #OWASSRF #ProxyNotShell

  20. Flinke beschuldiging van : de mitigations die had aanbevolen voor de Exchange-kwetsbaarheid zijn te omzeilen, wat de reden zou zijn dat Rackspace in december getroffen is door een grote cyberaanval. Het bedrijf installeerde de patch namelijk niet, maar vertrouwde op die mitigations.

    agconnect.nl/artikel/rackspace

  21. Flinke beschuldiging van #Rackspace: de mitigations die #Microsoft had aanbevolen voor de Exchange-kwetsbaarheid #ProxyNotShell zijn te omzeilen, wat de reden zou zijn dat Rackspace in december getroffen is door een grote cyberaanval. Het bedrijf installeerde de patch namelijk niet, maar vertrouwde op die mitigations.

    agconnect.nl/artikel/rackspace

  22. Flinke beschuldiging van #Rackspace: de mitigations die #Microsoft had aanbevolen voor de Exchange-kwetsbaarheid #ProxyNotShell zijn te omzeilen, wat de reden zou zijn dat Rackspace in december getroffen is door een grote cyberaanval. Het bedrijf installeerde de patch namelijk niet, maar vertrouwde op die mitigations.

    agconnect.nl/artikel/rackspace

  23. Flinke beschuldiging van #Rackspace: de mitigations die #Microsoft had aanbevolen voor de Exchange-kwetsbaarheid #ProxyNotShell zijn te omzeilen, wat de reden zou zijn dat Rackspace in december getroffen is door een grote cyberaanval. Het bedrijf installeerde de patch namelijk niet, maar vertrouwde op die mitigations.

    agconnect.nl/artikel/rackspace

  24. Flinke beschuldiging van #Rackspace: de mitigations die #Microsoft had aanbevolen voor de Exchange-kwetsbaarheid #ProxyNotShell zijn te omzeilen, wat de reden zou zijn dat Rackspace in december getroffen is door een grote cyberaanval. Het bedrijf installeerde de patch namelijk niet, maar vertrouwde op die mitigations.

    agconnect.nl/artikel/rackspace

  25. Hostingreus Rackspace had de grote -kwetsbaarheid niet gepatcht, maar vertrouwde op beperkende maatregelen van . Die mitigations zijn echter te omzeilen, wat de softwareleverancier volgens Rackspace níet heeft aangegeven.
    agconnect.nl/artikel/rackspace

  26. Hostingreus Rackspace had de grote #Exchange-kwetsbaarheid #ProxyNotShell niet gepatcht, maar vertrouwde op beperkende maatregelen van #Microsoft. Die mitigations zijn echter te omzeilen, wat de softwareleverancier volgens Rackspace níet heeft aangegeven.
    agconnect.nl/artikel/rackspace

  27. Hostingreus Rackspace had de grote #Exchange-kwetsbaarheid #ProxyNotShell niet gepatcht, maar vertrouwde op beperkende maatregelen van #Microsoft. Die mitigations zijn echter te omzeilen, wat de softwareleverancier volgens Rackspace níet heeft aangegeven.
    agconnect.nl/artikel/rackspace

  28. Hostingreus Rackspace had de grote #Exchange-kwetsbaarheid #ProxyNotShell niet gepatcht, maar vertrouwde op beperkende maatregelen van #Microsoft. Die mitigations zijn echter te omzeilen, wat de softwareleverancier volgens Rackspace níet heeft aangegeven.
    agconnect.nl/artikel/rackspace

  29. Jetzt patchen! Noch 60.000 Exchange-Server für ProxyNotShell-Attacken anfällig

    Sicherheitsforscher warnen vor verwundbaren Exchange-Servern. 30.000 davon sind in Europa – der Großteil in Deutschland. Sicherheitspatches sind verfügbar.

    heise.de/news/Jetzt-patchen-No

    #MicrosoftExchange #Patches #ProxyNotShell #Security #Sicherheitslücken #Updates #News

  30. Jetzt patchen! Noch 60.000 Exchange-Server für ProxyNotShell-Attacken anfällig

    Sicherheitsforscher warnen vor verwundbaren Exchange-Servern. 30.000 davon sind in Europa – der Großteil in Deutschland. Sicherheitspatches sind verfügbar.

    heise.de/news/Jetzt-patchen-No

    #MicrosoftExchange #Patches #ProxyNotShell #Security #Sicherheitslücken #Updates #News

  31. Jetzt patchen! Noch 60.000 Exchange-Server für ProxyNotShell-Attacken anfällig

    Sicherheitsforscher warnen vor verwundbaren Exchange-Servern. 30.000 davon sind in Europa – der Großteil in Deutschland. Sicherheitspatches sind verfügbar.

    heise.de/news/Jetzt-patchen-No

    #MicrosoftExchange #Patches #ProxyNotShell #Security #Sicherheitslücken #Updates #News

  32. Jetzt patchen! Noch 60.000 Exchange-Server für ProxyNotShell-Attacken anfällig

    Sicherheitsforscher warnen vor verwundbaren Exchange-Servern. 30.000 davon sind in Europa – der Großteil in Deutschland. Sicherheitspatches sind verfügbar.

    heise.de/news/Jetzt-patchen-No

    #MicrosoftExchange #Patches #ProxyNotShell #Security #Sicherheitslücken #Updates #News

  33. Jetzt patchen! Noch 60.000 Exchange-Server für ProxyNotShell-Attacken anfällig

    Sicherheitsforscher warnen vor verwundbaren Exchange-Servern. 30.000 davon sind in Europa – der Großteil in Deutschland. Sicherheitspatches sind verfügbar.

    heise.de/news/Jetzt-patchen-No

    #MicrosoftExchange #Patches #ProxyNotShell #Security #Sicherheitslücken #Updates #News

  34. @shadowserver
    ⬆️ ⬆️ Toujours des (milliers de) serveurs, y compris en France 🇫🇷 , qui n'ont pas été mis à jour contre les vulnérabilités #Exchange #ProxyNotShell #CVE_2022_41082

  35. @shadowserver
    ⬆️ ⬆️ Toujours des (milliers de) serveurs, y compris en France 🇫🇷 , qui n'ont pas été mis à jour contre les vulnérabilités #Exchange #ProxyNotShell #CVE_2022_41082

  36. @shadowserver
    ⬆️ ⬆️ Toujours des (milliers de) serveurs, y compris en France 🇫🇷 , qui n'ont pas été mis à jour contre les vulnérabilités #Exchange #ProxyNotShell #CVE_2022_41082

  37. @shadowserver
    ⬆️ ⬆️ Toujours des (milliers de) serveurs, y compris en France 🇫🇷 , qui n'ont pas été mis à jour contre les vulnérabilités #Exchange #ProxyNotShell #CVE_2022_41082

  38. @shadowserver
    ⬆️ ⬆️ Toujours des (milliers de) serveurs, y compris en France 🇫🇷 , qui n'ont pas été mis à jour contre les vulnérabilités #Exchange #ProxyNotShell #CVE_2022_41082

  39. New reporting on #ProxyNotShell by Palo Alto's Unit42!
    🔗unit42.paloaltonetworks.com/th

    Key points:

    🗓️​ Threat activity starting in late November
    ➡️​ Download of renamed Putty
    ➡️​ Anydesk execution from `C:\ProgramData\`
    ➡️​ Account creation (`admon`)
    ➡️​ Credential Dumping via Task Manager
    🛡️​ Detection/Hunting Op: `w3wp` process abuse

    #ThreatIntel #CTI #DetectionEngineering