Thanks @Volexity for the real world info on these horrible MSExchange vulnerabilities. The exploitation URL info and start date for known bad activity are great starting points for review. We see many of those IPs being used for a lot of unrelated dodgy activity in our logs.
Volexity has identified multiple 0-day exploits in Microsoft Exchange resulting in authentication bypass and RCE. Actively exploited in the wild since at least January 2021. More here: https://t.co/nnCkaYRPRm
#threatintel#dfir#infosec