ProxyLogon (Mar 2021): Exchange Server Zero-Days Exploited at Massive Scale
On March 2, 2021, Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, collectively known as...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
On March 2, 2021, Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, collectively known as...
On-premises Exchange servers were exploited repeatedly from 2021 to 2022. If you've moved mailboxes to Exchange Online, you may be able to retire your last...
Exchange Server exploitation typically results in web shells and suspicious processes spawned by IIS worker processes. These are the key detections.
The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of...
In March 2021, a group of hackers gained access to Verkada, a cloud-based security camera company, and viewed live feeds from roughly 150,000 cameras at...
Hardcoded credentials in scripts, configuration files and repositories are one of the easiest ways for attackers to escalate. Here is how to find them...
Exposed administrator credentials are often used soon after discovery. Detecting both the exposure and the misuse helps you respond before damage spreads.
The short version: In 2021, hackers accessed about 150,000 security cameras — in hospitals, schools and factories — by finding a single "super admin"...
In January 2021, email security company Mimecast disclosed that a certificate it used to authenticate certain products to Microsoft 365 Exchange Online had...
Third-party applications connected to Exchange Online can read, send or manage mail across your organization. Here is how to review them.
A compromised third-party integration can access your tenant with the app's permissions. These detections focus on unusual behavior by third-party apps.
The short version: In 2021, Mimecast — an email security company — disclosed that a digital certificate its products used to connect to customers' Microsoft...
On December 13, 2020, the world learned that attackers had compromised SolarWinds' Orion network monitoring software and inserted a backdoor — later called...
The SolarWinds attackers used stolen AD FS token-signing certificates to forge SAML tokens (Golden SAML) and access Microsoft 365. Moving authentication...
Golden SAML attacks forge tokens with a stolen AD FS signing certificate, letting attackers sign in to Microsoft 365 as anyone. These detections help...
The short version: In 2020, Russian intelligence hid malicious code inside updates for SolarWinds software used by thousands of organizations. For a smaller...
After SolarWinds was discovered in December 2020, Microsoft and incident responders described a key technique the attackers used in Microsoft 365: abusing...
Service principals and app registrations can hold powerful permissions with little oversight. Here is how to audit them in Entra ID.
Attackers who compromise applications or service principals can access data across a tenant without user sign-ins. Detecting credential and permission...
The short version: In the SolarWinds attack, intruders read email by hijacking applications connected to Microsoft 365 rather than user accounts. Apps and...
In November 2020, AWS Network Firewall became generally available — a managed, stateful network firewall and intrusion prevention service for Amazon VPCs.
A centralized inspection VPC lets one AWS Network Firewall deployment filter traffic for many VPCs. Here is the common architecture and setup sequence.
Egress filtering is one of the most effective controls against data exfiltration and malware. Use this checklist to put it in place across AWS VPCs.
The short version: Cloud servers can usually connect to anywhere on the internet by default. Attackers rely on that to steal data and control compromised...