#ProxyLogon
Hackers injected keyloggers into over 70 Microsoft Exchange servers, exploiting ProxyShell/ProxyLogon. Two keyloggers sent stolen data locally or externally (Telegram/DNS). Victims included government & financial institutions across 26 countries.#ProxyShellExchangeHack
June 25, 2025 at 6:04 AM
Salt Typhoon exploited unpatched Microsoft Exchange (ProxyLogon), Ivanti, & Sophos flaws to attack 9 US telecoms. Despite a 2021 patch, 91% of ~30,000 servers remain vulnerable.#SaltTyphoonVulnerabilities
January 28, 2025 at 6:17 AM
Salt Typhoon (FamousSparrow, etc.) targets global telecoms & governments. This Chinese state-sponsored group exploits vulnerabilities (e.g., ProxyLogon) using PowerShell/VB scripting. AttackIQ offers a threat emulation template.#SaltTyphoonThreat
March 20, 2025 at 12:10 PM
Yemeni national Rami Khaled Ahmed (36) faces 15 years in prison for deploying Black Kingdom ransomware, targeting 1,500 systems worldwide, including U.S. businesses and healthcare providers. He exploited ProxyLogon and Pulse Secure VPN vulnerabilities.#BlackKingdomRansomware
May 3, 2025 at 8:01 AM
Salt Typhoon お気に入り脆弱性の影響を受けるExchange サーバー、未解決のままが91%残る
#CybersecurityNews
www.theregister.com/2025/01/23/p...
ProxyLogon, one of Salt Typhoon's favorites, still wide open
But we mean, you've had nearly four years to patch
www.theregister.com
January 23, 2025 at 11:47 PM
Eagerbee malware, linked to CoughingDown, targets Middle Eastern gov't & ISPs. Using DLL hijacking (via Themes service etc.), it delivers a backdoor with 5 plugins for extensive system control (file/process management, remote access, etc.). ProxyLogon (CVE-2021-26855) may be used for initial access.
January 6, 2025 at 3:03 PM
Preventing Data Loss: Backup and Recovery Strategies for Exchange Server Administrators
Preventing Data Loss: Backup and Recovery Strategies for Exchange Server Administrators
Cyber threats are on the rise! Learn how ransomware attacks and vulnerabilities like ProxyLogon are causing data loss in Exchange Servers
thehackernews.com
January 19, 2024 at 11:29 AM
One of Salt Typhoon's favorite flaws still wide open on 91% of at-risk Exchange Servers
ProxyLogon, one of Salt Typhoon's favorites, still wide open
But we mean, you've had nearly four years to patch
buff.ly
January 24, 2025 at 11:12 PM
ANALYSIS TIME - The Register's Jessica Lyons Presents:

One of Xina's Salt Typhoons hacking group's favorite flaws still wide open on 91% of at-risk Exchange Servers (Failure by #Western IT to patch exploitable vulnerabilities used by enemies still ongoing)

www.theregister.com/2025/01/23/p...
ProxyLogon, one of Salt Typhoon's favorites, still wide open
But we mean, you've had nearly four years to patch
www.theregister.com
January 24, 2025 at 1:41 AM
StrikeShark campaign deploys SharkLoader to install Cobalt Strike Beacon on compromised systems, targeting diplomatic, government, and software development orgs via exploits, droppers, and DLL side-loading. #Japan #StrikeShark #SharkLoader
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly observed campaign tracked as StrikeShark is delivering the previously undocumented SharkLoader malware to deploy Cobalt Strike Beacon on compromised systems. The activity targets organizations across multiple countries and uses public exploit chains, malicious droppers, and DLL side-loading to gain access and maintain control. #StrikeShark #SharkLoader #CobaltStrikeBeacon #ProxyLogon #Openfire #GeoServer...
www.hendryadrian.com
June 27, 2026 at 3:00 AM
🟢 Inside ProxyLogon: How the Microsoft Exchange Server Vulnerability Works and How Hackers Exploit It

🗨️ When attackers discover a zero‑day vulnerability in some piece of software, the fun begins. And if it happens in very po…

#security
Inside ProxyLogon: How the Microsoft Exchange Server Vulnerability Works and How Hackers Exploit It
Read more
hackmag.com
July 15, 2026 at 12:00 AM
US indicts Black Kingdom ransomware operator: technical analysis of ProxyLogon exploitation and law enforcement response

details here: securebulletin.com/us-indicts-b...
May 4, 2025 at 10:56 AM
CVE-2021-27065: Microsoft Exchange Server Remote Code Execution Vulnerability dev.to/freedom_code...
CVE-2021-27065: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
dev.to
July 1, 2025 at 11:28 PM
National Oil Ethiopia PLC hit by a major ransomware attack via Exchange ProxyLogon exploit. Attackers disabled Kaspersky, compromised Veeam backups, and stole 800GB ERP data across four databases. #NationalOilEthiopia #ProxyLogon #Ethiopia
National Oil Ethiopia PLC Suffers Major Data Breach
National Oil Ethiopia PLC (NOC) reportedly suffered a major data breach and ransomware attack after a threat actor detailed an eight-step intrusion on a hacker forum. The attacker says they exploited an Exchange ProxyLogon vulnerability to escalate privileges, disable Kaspersky, compromise Veeam backups, deploy ransomware, and exfiltrate four databases including an...
www.hendryadrian.com
March 25, 2026 at 3:20 PM
Threat actor ByteToBreach claims full takeover of National Oil Ethiopia’s infrastructure via Exchange ProxyLogon exploit, exfiltrating 800GB of data including a 500GB ERP database, compromising Veeam and Kaspersky, and deploying ransomware. #Ethiopia #ERPAttack
Alleged Full Infrastructure Compromise of National Oil Ethiopia With 800GB ERP Database Exfiltration, Veeam and Kaspersky Compromise, and Ransomware Deployment
Threat actor ByteToBreach claims a full infrastructure takeover of National Oil Ethiopia PLC, achieving full Active Directory admin access and deploying ransomware after an 8-step intrusion. The actor alleges exfiltration of over 800 GB of data—including a 500 GB ERP database—and reports compromises of Veeam backup infrastructure and the Kaspersky security...
www.hendryadrian.com
March 25, 2026 at 12:40 AM
Bulletproof Hosting Watch — week of 2026-07-04

Pfcloud UG (AS51396) surged ~2.6x to 11,500+ honeypot events from Dutch IPs running per-node port scan profiles. Proton66 (AS198953) running RDP credential stuffing out of Moscow (mstshash=Domain). Private Layer (AS51852) probing for ProxyLogon via […]
Original post on mastodon.social
mastodon.social
July 6, 2026 at 10:56 AM
ProxyLogon, one of Salt Typhoon's favorites, still wide open https://buff.ly/4au0h7k
ProxyLogon, one of Salt Typhoon's favorites, still wide open
But we mean, you've had nearly four years to patch
buff.ly
January 30, 2025 at 5:31 PM
ToddyCat Malware Compromises Microsoft Exchange Servers using ProxyLogon Vulnerability
ToddyCat Malware Compromises Microsoft Exchange Servers using ProxyLogon Vulnerability
cybersecuritynews.com
January 7, 2026 at 11:42 AM
Hackers Using ProxyLogon & ProxyShell To Attack Microsoft Exchange Servers
Hackers Using ProxyLogon & ProxyShell To Attack Microsoft Exchange Servers
Hackers attack Microsoft Exchange servers because they often contain sensitive communication data that can be exploited for several illicit
cybersecuritynews.com
July 5, 2024 at 11:40 AM
Feed: "GBHackers Security | #1 Globally Trusted Cyber Security News Platform"
By: Mayura Kathir on Wednesday, January 7, 2026
ToddyCat Malware Exploits ProxyLogon to Compromise Microsoft Exchange Servers
ToddyCat, a sophisticated cyber-espionage threat group also known as Websiic and Storm-0247, has emerged as a significant risk to organizations across Europe and Asia.
gbhackers.com
January 7, 2026 at 9:24 PM