A catastrophic series of zero-day vulnerabilities (including CVE-2021-26855) in on-premises Microsoft Exchange software allowed Chinese state-sponsored actors to systematically web-shell thousands of corporate email servers across Australia, triggering an unprecedented urgent national remediation push by the ACSC.