logo

One of Salt Typhoon's favorite flaws still wide open on 91% of at-risk Exchange Servers

ID: 763f3bee-8bc2-57bf-b049-9a648585193e

STIX ID: report--763f3bee-8bc2-57bf-b049-9a648585193e

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-01-23

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Tenable and industry reporting show that China-linked groups (Salt Typhoon and others) continue to exploit unpatched Microsoft Exchange servers (notably CVE-2021-26855/ProxyLogon) and other flaws to gain persistent access to US telecom, government, and critical infrastructure networks using custom malware (GhostSpider, SnappyBee, Masol, Demodex); despite patches being available for years, a large majority of public-facing vulnerable Exchange instances remain unpatched, enabling ongoing campaigns and significant national-security risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.