Kevin Beaumont · @GossiTheDog
31102 followers · 1146 posts · Server cyberplace.social

in Exchange Server fingered in UK Electoral Commission hack.

TechCrunch found Electoral Commission were using on prem Exchange.

I had a look via @shodan history feature - their Exchange Server, with OWA enabled, was online until later in 2022 (when the incident began) - and didn't have ProxyNotShell patches installed, as Microsoft hadn't released them.

The mitigations MS released were bypassable, as seen in the Rackspace Hosted Exchange hack.

techcrunch.com/2023/08/09/pars

#proxynotshell

Last updated 1 year ago

Stef Rand · @techieStef
133 followers · 7 posts · Server infosec.exchange

Our monthly Intelligence Insight for January is out!

redcanary.com/blog/intelligenc

We saw a ton of testing at the end of the year which we think boosted Mimikatz & BloodHound pretty high on our trending threats list.

We observed increased exploitation of Exchange servers at the end of the year & have shared some thoughts on that as well!

#proxynotshell

Last updated 2 years ago

(the real) Didi B. ⭐️ · @didib
169 followers · 1359 posts · Server swiss.social
Unveiled Security · @unveiledsec
1 followers · 2 posts · Server infosec.exchange

On Dec 22, 2022, Unit42 released a threat brief on the new OWASSRF exploit method for Microsoft Exchange Server published by CrowdStrike

Threat Brief: OWASSRF Vulnerability Exploitation

unit42.paloaltonetworks.com/th

#owassrf #proxynotshell #cybersecurity #cyberthreatintelligence

Last updated 2 years ago

's new exploit method to bypass mitigations to is very interesting. I am going to need to build some new IOC for this.

crowdstrike.com/blog/owassrf-e

#playransomware #proxynotshell #cybersecurity

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
22191 followers · 1049 posts · Server cyberplace.social

Interesting one on my honeypots - somebody popped a box with and added an Exchange transport rule to redirect any emails mentioning cryptocurrency to an external mailbox.

No webshells. Full chain appeared automated based on time stamps.

#proxynotshell

Last updated 2 years ago

Eveline Meijer · @EvelineMeijer
542 followers · 735 posts · Server mstdn.social

Flinke beschuldiging van : de mitigations die had aanbevolen voor de Exchange-kwetsbaarheid zijn te omzeilen, wat de reden zou zijn dat Rackspace in december getroffen is door een grote cyberaanval. Het bedrijf installeerde de patch namelijk niet, maar vertrouwde op die mitigations.

agconnect.nl/artikel/rackspace

#proxynotshell #Microsoft #rackspace

Last updated 2 years ago

AG Connect · @AGConnect
206 followers · 296 posts · Server mstdn.social

Hostingreus Rackspace had de grote -kwetsbaarheid niet gepatcht, maar vertrouwde op beperkende maatregelen van . Die mitigations zijn echter te omzeilen, wat de softwareleverancier volgens Rackspace níet heeft aangegeven.
agconnect.nl/artikel/rackspace

#Microsoft #proxynotshell #Exchange

Last updated 2 years ago

Unveiled Security · @unveiledsec
1 followers · 2 posts · Server infosec.exchange

The Assault on Microsoft Exchange Server

Microsoft Exchange Server is an attractive target for threat actors trying to gain access to corporate networks to perform discovery operations and to deploy malware, including ransomware.

unveiledsecurity.com/2023/01/0

#microsoftexchange #proxyshell #proxylogon #vulnerabilities #proxynotshell #owassrf

Last updated 2 years ago

I'm sure someone has already posted about this and I just missed it, but Rackspace Blames Zero-Day Exploit for Ransomware Hit Success.
They are also sort of blaming Microsoft a little bit.

Hosting Giant Says Microsoft's Patch Notes Didn't Detail Remote-Code Execution Risk

Remember how it broke that malicious actors had found ways to skirt around the ProxyNotShell URL filtering mitigatsion provided by Microsoft? Do you also remember how anybody in the community knew it was only a matter of time before this happened because there are always ways to get around filters like this?
Ah, anyway, Rackspace was relying on the URL filtering and hadn't actually patched.

Rackspace says it didn't immediately apply the Exchange patch released last November by Microsoft because of multiple user reports that the patch was causing errors, including leaving Microsoft Outlook Web Access - OWA - inaccessible. Pending a fully working patch, the company says it instead used mitigations recommended by Microsoft.

#infosec #proxynotshell #rackspace #m365 #o365 #exchange #msexchange

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
21989 followers · 1024 posts · Server cyberplace.social

Okay, we have a update from them which confirms my reporting the servers didn’t have the patch installed - instead they were relying on the Microsoft mitigation - which was bypassable, but Microsoft hadn’t told anybody this. The attackers used the bypass to ransomware their Hosted Exchange environment.

bankinfosecurity.com/rackspace

#rackspace #proxynotshell

Last updated 2 years ago

heise online · @heiseonline
38499 followers · 1121 posts · Server mastodon.social

Jetzt patchen! Noch 60.000 Exchange-Server für ProxyNotShell-Attacken anfällig

Sicherheitsforscher warnen vor verwundbaren Exchange-Servern. 30.000 davon sind in Europa – der Großteil in Deutschland. Sicherheitspatches sind verfügbar.

heise.de/news/Jetzt-patchen-No

#microsoftexchange #patches #proxynotshell #security #sicherheitslucken #updates #news

Last updated 2 years ago

damien :donor: · @damien
519 followers · 2090 posts · Server infosec.exchange

ICYMI, Unit42 published a Threat Brief with analysis of , an exploit method for Microsoft Exchange Server related to on December 22.

unit42.paloaltonetworks.com/th

#owassrf #proxynotshell

Last updated 2 years ago

Still around 66K IPs found with likely CVE-2022-41082 vulnerable MS Exchange instances. Most in the United States (16K IPs, 37% of discoverable instances in US) and Germany (12K IPs, 29% of discoverable instances in DE). Patch now!

Track latest scan results here: t.co/tsRTE5fLnL

Background:
infosec.exchange/@shadowserver

#proxynotshell

Last updated 2 years ago

Thomas Lee ✅ :patreon: · @DoctorDNS
797 followers · 1014 posts · Server masto.ai

The latest A Daily Dose of PowerShell! paper.li/doctordns/1580827252? Thanks to @ArgusTaft@twitter.com

#proxynotshell #powershell

Last updated 2 years ago

Dissent Doe :cupofcoffee: · @PogoWasRight
1050 followers · 121 posts · Server infosec.exchange
Kevin Beaumont · @GossiTheDog
21075 followers · 1039 posts · Server cyberplace.social

One of my Exchange honeypots got popped with the OWASSRF exploit. The user was a deliberate Redline infected user from a few months ago.

#proxynotshell #threatintel

Last updated 2 years ago

GRUzzly Bear :verified: · @1nternaut
239 followers · 107 posts · Server infosec.exchange

RT @Shadowserver@twitter.com

We are reporting out Microsoft Exchange servers still likely vulnerable to CVE-2022-41082 . Nearly 70K IPs found without MS patches applied (based on version info). Previously recommended mitigation techniques can be bypassed by attackers

shadowserver.org/what-we-do/ne

#proxynotshell

Last updated 2 years ago

LastBreach · @lastbreach
4 followers · 2 posts · Server infosec.exchange

Frohe Weihnachten und guten Rutsch - zum Jahreswechsel noch die wichtigsten Infos. Warnung und Update zu Schwachstellen, Tresor Daten gestohlen, 's Quellcode geklaut, Datenpanne bei und weitere .

lastbreach.de/blog/die-infosec

#exchange #proxynotshell #lastpass #okta #socialblade #news

Last updated 2 years ago