logo

The ticking time bomb of Microsoft Exchange Server 2013

ID: b9e8c23f-8e62-57bf-b76f-33da73596355

STIX ID: report--b9e8c23f-8e62-57bf-b76f-33da73596355

Feed Name: DoublePulsar

Threat Score
75/100

Date Published: 2023-12-22

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

This report details opportunistic ransomware incidents impacting internet-facing Microsoft Exchange Server 2013 instances: attackers obtained network access and code execution (likely via known post-authentication Exchange vulnerabilities), and many organizations—around 25,000 IPs with OWA exposed, including government systems—remain vulnerable due to end-of-support software and scanner blind spots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.