The exploitation of Microsoft Exchange Server zero-day vulnerabilities comprised a huge portion of threats Cisco Talos Incident Response (CTIR) observed this past quarter. The majority of these incidents involved scanning and not post-compromise behavior, such as file encryption or evidence of exfiltration. Ransomware continued to be a persistent and growing problem, including MountLocker, Zeppelin and Avaddon. Attackers targeted the health care sector most often, with nearly four times as many incidents as the next most targeted verticals education and technology.”]
Source: https://blog.talosintelligence.com/2021/06/quarterly-report-incident-response.html

