The U.S. Cybersecurity and Infrastructure Security Agency issued an emergency directive warning of “active exploitation” of the vulnerabilities. The alert comes on the heels of Microsoft’s disclosure that China-based hackers were exploiting unknown software bugs in Exchange server to steal sensitive data from select targets. Researchers at Huntress Labs have also sounded the alarm about mass exploitation of Exchange servers, noting that over 350 web shells have been discovered across approximately 2,000 vulnerable servers. The latest development indicates a much larger spread that extends beyond the “limited and targeted” attacks reported by Microsoft earlier this week.
Source: https://thehackernews.com/2021/03/cisa-issues-emergency-directive-on-in.html

