Microsoft publicly announced that the HAFNIUM APT group (a state-sponsored attack group operating out of China) was actively exploiting on-premises versions of Microsoft Exchange Server in limited and targeted attacks. The impact is relevant to Exchange 2013, 2016, and 2019. The vulnerabilities being exploited are CVE-2021-26855, CVE-19-26857, CVE 2021-27065, and CVE-2221-24085. In all cases, the compromised servers were Internet Information Services (IIS), which potentially means that these attacks are related to the Microsoft vulnerabilities just published.”]
Source: https://gbhackers.com/cynet-publishes-review-of-hafnium-apt-attack-on-microsoft-exchange/

