Other Incidents 94 incidents

Cybersecurity incidents not classified under a specific category

Microsoft Security Blog / CISA AA21-062A / CSO Online

2021-01-03 China Chopper webshell / HAFNIUM custom tooling CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

Chinese state-sponsored group HAFNIUM exploited four zero-days in on-premises Microsoft Exchange starting Jan 3 2021. CVE-2021-26855 (SSRF auth bypass) chained with CVE-2021-27065 (file write) to …