Mapping MITRE ATT&CK to the Microsoft Exchange Zero-Day Exploits
ID: 82c2ffc9-351c-5546-adb6-d76b571d77a4
STIX ID: report--82c2ffc9-351c-5546-adb6-d76b571d77a4
Feed Name: ReliaQuest Blog
This blog maps Microsoft’s March 2021 Exchange Server zero-day compromises to the MITRE ATT&CK framework, detailing four exploited CVEs (including CVE-2021-26855) used by HAFNIUM and multiple other actors to gain initial access, deploy web shells for persistence, and exfiltrate email data via C2. It highlights active exploitation at scale (Microsoft estimated ~30,000 compromised organizations), recommends immediate patching and investigation, and provides detection and mitigation guidance including Microsoft updates and scanning tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
