Home/Incidents/Microsoft (Exchange Server)

Microsoft (Exchange Server)

2 Mar 2021 · National · Technology
Malware / Exploit CRITICAL ✓ Verified

What happened

A catastrophic series of zero-day vulnerabilities (including CVE-2021-26855) in on-premises Microsoft Exchange software allowed Chinese state-sponsored actors to systematically web-shell thousands of corporate email servers across Australia, triggering an unprecedented urgent national remediation push by the ACSC.

Incident details

Organisation
Microsoft (Exchange Server)
Date
2 Mar 2021
Attack type
Malware / Exploit
Severity
CRITICAL
Sector
Technology
State
National
Records affected
Unknown
Threat actor
HAFNIUM (APT)

Source

nine.com.au ↗
← Back to all incidents