{"id":39917,"date":"2021-03-09T08:18:00","date_gmt":"2021-03-09T08:18:00","guid":{"rendered":"http:\/\/8e39b76b-fd6b-415b-9321-67ddfce0a102"},"modified":"2021-03-09T08:18:00","modified_gmt":"2021-03-09T08:18:00","slug":"everything-you-need-to-know-about-the-microsoft-exchange-server-hack","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/","title":{"rendered":"Everything you need to know about the Microsoft Exchange Server hack"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/hub\/i\/r\/2021\/03\/08\/3b4af53b-ab1a-45f0-a291-7bfe58e08eff\/thumbnail\/770x578\/3741930e80b9eaa45e1951eb69036fdb\/screenshot-2021-03-08-at-10-04-18.png\" class=\"ff-og-image-inserted\"><\/div>\n<p>Four zero-day vulnerabilities in Microsoft Exchange Server are being <a href=\"https:\/\/www.zdnet.com\/article\/update-immediately-microsoft-rushes-out-patches-for-exchange-server-zero-day-attacks\/\" target=\"_blank\" rel=\"noopener noreferrer\">actively exploited<\/a> by a state-sponsored threat group from China and appear to have been adopted by other cyberattackers in widespread attacks.<\/p>\n<div class=\"relatedContent alignRight\">\n<h3 class=\"heading\"> <span class=\"int\">More Coverage<\/span> <\/h3>\n<\/p><\/div>\n<p>While in no way believed to be connected to the SolarWinds <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-weve-found-three-more-pieces-of-malware-used-by-the-solarwinds-attackers\/\" target=\"_blank\" rel=\"noopener noreferrer\">supply chain attack<\/a> that has impacted an estimated 18,000 organizations worldwide &#8212; so far &#8212; there is concern that lags in patching vulnerable servers could have a similar impact, or worse, on businesses.&nbsp;<\/p>\n<p><strong>Also:&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/best-vpn-services-for-2021-safe-and-fast-dont-come-for-free\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Best VPNs<\/strong><\/a><strong>&nbsp;\u2022&nbsp;<\/strong><a href=\"https:\/\/www.zdnet.com\/article\/best-security-key\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Best security keys<\/strong><\/a><strong>&nbsp; \u2022 <\/strong><a href=\"https:\/\/www.zdnet.com\/article\/best-antivirus\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Best antivirus<\/strong><\/a><\/p>\n<p>Here is everything you need to know about the security issues and our guide will be updated as the story develops.&nbsp;<\/p>\n<h3>What happened?<\/h3>\n<p>Microsoft told <a href=\"https:\/\/krebsonsecurity.com\/2021\/03\/a-basic-timeline-of-the-exchange-mass-hack\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">security expert Brian Krebs<\/a> that the company was made aware of four zero-day bugs in &#8220;early&#8221; January.&nbsp;<\/p>\n<p>A DEVCORE researcher, credited with finding two of the security issues, appears to have reported them around January 5. Going under the handle &#8220;Orange Tsai,&#8221; the researcher&nbsp;<a href=\"https:\/\/twitter.com\/orange_8361\/status\/1346401788811825153\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">tweeted<\/a>:<\/p>\n<blockquote readability=\"6\">\n<p>&#8220;Just report a pre-auth RCE chain to the vendor. This might be the most serious RCE I have ever reported.&#8221;<\/p>\n<\/blockquote>\n<p>According&nbsp;<a href=\"https:\/\/www.volexity.com\/blog\/2021\/03\/02\/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">to Volexity<\/a>, attacks using the four zero-days may have started as early as January 6, 2021. Dubex&nbsp;<a href=\"https:\/\/www.dubex.dk\/aktuelt\/nyheder\/please-leave-an-exploit-after-the-beep\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">reported<\/a> suspicious activity on Microsoft Exchange servers in the same month.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\"> <\/section>\n<p>On March 2, <a href=\"https:\/\/www.zdnet.com\/article\/update-immediately-microsoft-rushes-out-patches-for-exchange-server-zero-day-attacks\/\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft released patches<\/a> to tackle the four severe vulnerabilities in Microsoft Exchange Server software. At the time, the company said that the bugs were being actively exploited in &#8220;limited, targeted attacks.&#8221; <\/p>\n<p>Microsoft Exchange Server is an email inbox, calendar, and collaboration solution. Users range from enterprise giants to small and medium-sized businesses worldwide.&nbsp; <\/p>\n<p>While fixes have <a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/02\/multiple-security-updates-released-for-exchange-server\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">been issued<\/a>, the scope of potential Exchange Server compromise depends on the speed and uptake of patches &#8212; and the number of estimated victims continues to grow.&nbsp; <\/p>\n<h3>What are the vulnerabilities and why are they important?<\/h3>\n<p>The <a href=\"https:\/\/www.tenable.com\/blog\/cve-2021-26855-cve-2021-26857-cve-2021-26858-cve-2021-27065-four-microsoft-exchange-server-zero-day-vulnerabilities\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">critical vulnerabilities<\/a> impact on-premise Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019. However, Exchange Online is not affected.&nbsp; <\/p>\n<ul>\n<li><strong><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-26855\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">CVE-2021-26855<\/a>: CVSS 9.1:<\/strong> a Server Side Request Forgery (SSRF) vulnerability leading to crafted HTTP requests being sent by unauthenticated attackers. Servers need to be able to accept untrusted connections over port 443 for the bug to be triggered.<\/li>\n<li> <strong><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-26857\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">CVE-2021-26857<\/a>: CVSS 7.8:<\/strong> an insecure deserialization vulnerability in the Exchange Unified Messaging Service, allowing arbitrary code deployment under SYSTEM. However, this vulnerability needs to be combined with another or stolen credentials must be used.<\/li>\n<li> <strong><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-26858\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">CVE-2021-26858<\/a>: CVSS 7.8:<\/strong> a post-authentication arbitrary file write vulnerability to write to paths.&nbsp;<\/li>\n<li> <strong><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-27065\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">CVE-2021-27065<\/a>: CVSS 7.8:<\/strong> a post-authentication arbitrary file write vulnerability to write to paths.&nbsp;<\/li>\n<\/ul>\n<p>If used in an <strong>attack chain<\/strong>, all of these vulnerabilities can lead to Remote Code Execution (RCE), server hijacking, backdoors, data theft, and potentially further malware deployment. <\/p>\n<p>In summary, Microsoft says that attackers secure access to an Exchange Server either through these bugs or stolen credentials and they can then create a web shell to hijack the system and execute commands remotely.&nbsp; <\/p>\n<p>&#8220;These vulnerabilities are used as part of an attack chain,&#8221; Microsoft says. &#8220;The initial attack requires the ability to make an untrusted connection to Exchange server port 443. This can be protected against by restricting untrusted connections, or by setting up a VPN to separate the Exchange server from external access. Using this mitigation will only protect against the initial portion of the attack; other portions of the chain can be triggered if an attacker already has access or can convince an administrator to run a malicious file.&#8221;<\/p>\n<h3>Who is responsible for known attacks?<\/h3>\n<p>Microsoft says that attacks using the zero-day flaws have been <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2021\/03\/02\/new-nation-state-cyberattacks\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">traced back to Hafnium<\/a>.&nbsp; <\/p>\n<p>Hafnium is a state-sponsored advanced persistent threat (APT) group from China that is described by the company as a &#8220;highly skilled and sophisticated actor.&#8221;&nbsp; <\/p>\n<p>While Hafnium originates in China, the group uses a web of virtual private servers (VPS) located in the US to try and conceal its true location. Entities previously targeted by the group include think tanks, non-profits, defense contractors, and researchers.&nbsp;<\/p>\n<h3>Is it just Hafnium?&nbsp;<\/h3>\n<p>When zero-day vulnerabilities come to light and emergency security fixes are issued, if popular software is involved, the ramifications can be massive. Problems can often be traced back to awareness of new patches, slow uptake, or reasons why IT staff cannot apply a fix &#8212; whether this is because they are unaware that an organization is using software, third-party libraries, or components at risk, or potentially due to compatibility problems.&nbsp;<\/p>\n<p>Mandiant says further attacks <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-exchange-zero-day-vulnerabilities-exploited-in-attacks-against-us-local-govts-university\/\" target=\"_blank\" rel=\"noopener noreferrer\">against US targets<\/a> include local government bodies, a university, an engineering company, and retailers. The cyberforensics firm believes the vulnerabilities could be used for the purposes of ransomware deployment and data theft.&nbsp;<\/p>\n<p>Sources have told cybersecurity expert Brian Krebs that approximately <a href=\"https:\/\/www.zdnet.com\/article\/microsoft-exchange-zero-day-attacks-30000-servers-hit-already-says-report\/\" target=\"_blank\" rel=\"noopener noreferrer\">30,000 organizations<\/a> in the US have been hacked so far. Bloomberg estimates put this figure closer <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2021-03-07\/hackers-breach-thousands-of-microsoft-customers-around-the-world\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">to 60,000<\/a>, as of March 8. <\/p>\n<p>The <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-56321567\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">European Banking Authority<\/a> is one of the latest victims. Data may have been accessed from the agency&#8217;s email servers.&nbsp; <\/p>\n<p>The US Cybersecurity and Infrastructure Security Agency (CISA) says that the agency is &#8220;aware of threat actors using open source tools to search for vulnerable Microsoft Exchange Servers.&#8221;<\/p>\n<p>In an <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">update<\/a> on March 5, Microsoft said the company &#8220;continues to see increased use of these vulnerabilities in attacks targeting unpatched systems by multiple malicious actors beyond Hafnium.&#8221;<\/p>\n<p>The Biden Administration is expected to <a href=\"https:\/\/edition.cnn.com\/2021\/03\/06\/politics\/microsoft-hack-task-force\/index.html\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">form a task force<\/a> to explore the reported links between Microsoft Exchange attacks and China, according to CNN.&nbsp;<\/p>\n<h3>How can I check my servers and their vulnerability status? What do I do now?<\/h3>\n<p>Microsoft has urged IT administrators and customers to <a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/02\/multiple-security-updates-released-for-exchange-server\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">apply the security fixes<\/a> immediately. However, just because fixes are applied now, this does not mean that servers have not already been backdoored or otherwise compromised.<\/p>\n<p>Interim <a href=\"https:\/\/msrc-blog.microsoft.com\/2021\/03\/05\/microsoft-exchange-server-vulnerabilities-mitigations-march-2021\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">mitigation option guides<\/a> are also available if patching immediately is not possible.&nbsp; <\/p>\n<p>The Redmond giant has also published a script on <a href=\"https:\/\/github.com\/microsoft\/CSS-Exchange\/tree\/main\/Security\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">GitHub<\/a> available to IT administrators to run that includes <a href=\"https:\/\/www.zdnet.com\/article\/check-to-see-if-youre-vulnerable-to-microsoft-exchange-server-zero-days-using-this-tool\/\" target=\"_blank\" rel=\"noopener noreferrer\">indicators of compromise<\/a> (IOCs) linked to the four vulnerabilities. IoCs are listed separately <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/#scan-log\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">here<\/a>.&nbsp;<\/p>\n<p>On March 8, Microsoft released an <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/exchange-team-blog\/march-2021-exchange-server-security-updates-for-older-cumulative\/ba-p\/2192020\" target=\"_blank\" rel=\"noopener noreferrer\" data-component=\"externalLink\">additional set<\/a> of security updates that can be applied to older, unsupported Cumulative Updates (CUs) as a temporary measure.&nbsp;<\/p>\n<p>CISA issued an <a href=\"https:\/\/www.zdnet.com\/article\/cisa-issues-emergency-directive-to-agencies-deal-with-microsoft-exchange-bugs-now\/\" target=\"_blank\" rel=\"noopener noreferrer\">emergency directive<\/a> on March 3 that demanded federal agencies immediately analyze any servers running Microsoft Exchange and to apply the firm&#8217;s supplied fixes.&nbsp;<\/p>\n<p>If there are any indicators of suspicious behavior dating back as far as September 1, 2020, CISA requires agencies to disconnect them from the Internet to mitigate the risk of further damage. The FBI has also <a href=\"https:\/\/www.fbi.gov\/news\/pressrel\/press-releases\/statement-on-microsoft-exchange-server-vulnerabilities\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">released a statement<\/a> on the situation.<\/p>\n<p>Microsoft continues to investigate and as more information comes to light we will update.<\/p>\n<h3> Previous and related coverage <\/h3>\n<hr>\n<p><strong>Have a tip?<\/strong> Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0<\/p>\n<hr>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/everything-you-need-to-know-about-microsoft-exchange-server-hack\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Updated: Vulnerabilities are being exploited by Hafnium. Other cyberattackers are following suit.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":39918,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-39917","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Everything you need to know about the Microsoft Exchange Server hack 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Everything you need to know about the Microsoft Exchange Server hack 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-09T08:18:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png\" \/>\n\t<meta property=\"og:image:width\" content=\"770\" \/>\n\t<meta property=\"og:image:height\" content=\"578\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Everything you need to know about the Microsoft Exchange Server hack\",\"datePublished\":\"2021-03-09T08:18:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/\"},\"wordCount\":1140,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/\",\"name\":\"Everything you need to know about the Microsoft Exchange Server hack 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png\",\"datePublished\":\"2021-03-09T08:18:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png\",\"width\":770,\"height\":578},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Everything you need to know about the Microsoft Exchange Server hack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Everything you need to know about the Microsoft Exchange Server hack 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/","og_locale":"en_US","og_type":"article","og_title":"Everything you need to know about the Microsoft Exchange Server hack 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-03-09T08:18:00+00:00","og_image":[{"width":770,"height":578,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Everything you need to know about the Microsoft Exchange Server hack","datePublished":"2021-03-09T08:18:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/"},"wordCount":1140,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/","url":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/","name":"Everything you need to know about the Microsoft Exchange Server hack 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png","datePublished":"2021-03-09T08:18:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/03\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack.png","width":770,"height":578},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/everything-you-need-to-know-about-the-microsoft-exchange-server-hack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Everything you need to know about the Microsoft Exchange Server hack"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39917","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=39917"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39917\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/39918"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=39917"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=39917"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=39917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}