One of Salt Typhoon's favorite flaws still wide open on 91% of at-risk Exchange Servers
ID: 763f3bee-8bc2-57bf-b049-9a648585193e
STIX ID: report--763f3bee-8bc2-57bf-b049-9a648585193e
Feed Name: The Register (Security)
Tenable and industry reporting show that China-linked groups (Salt Typhoon and others) continue to exploit unpatched Microsoft Exchange servers (notably CVE-2021-26855/ProxyLogon) and other flaws to gain persistent access to US telecom, government, and critical infrastructure networks using custom malware (GhostSpider, SnappyBee, Masol, Demodex); despite patches being available for years, a large majority of public-facing vulnerable Exchange instances remain unpatched, enabling ongoing campaigns and significant national-security risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
