Microsoft says it first became aware of the problem in early January. The earliest known report came on Jan. 5, from a principal security researcher for security testing firm DEVCORE. Microsoft credits Volexity with reporting two of the four Exchange flaws that Microsoft patched on Mar. 2. The vulnerabilities the attackers exploited have been in the Microsoft Exchange Server code base for more than ten years. Microsoft had almost two months to push out the patch, or else help mitigate the threat before attackers started exploiting it indiscriminately.”]
Source: https://krebsonsecurity.com/2021/03/a-basic-timeline-of-the-exchange-mass-hack/

