Skip to content
Threat Feed

Product

Exchange Server

12 briefs RSS
high threat

NightEagle APT Targets Russian Organizations with GhostContainer Backdoor

The NightEagle APT group is actively targeting organizations by exploiting compromised VPN credentials, deploying the memory-resident GhostContainer backdoor on Exchange servers, and utilizing legitimate tunneling tools for lateral movement.

Exchange Server NightEagle apt exchange backdoor tunnel
3t 1c
critical threat

Microsoft September 2026 Patch Tuesday Addresses Two Actively Exploited Zero-Days

Microsoft's September 2026 update cycle addresses 974 vulnerabilities, including two privilege-escalation zero-days actively exploited in the wild and 20 potentially wormable RCE flaws.

exploited Windows +7 vulnerability-management patch-tuesday privilege-escalation
1t 2c
high advisory

Multiple Vulnerabilities in Microsoft Exchange Server

Microsoft Exchange Server contains multiple vulnerabilities that can be exploited by an authenticated remote attacker to achieve privilege escalation, arbitrary code execution, security control bypass, data manipulation, and denial-of-service.

PoC Exchange Server vulnerability microsoft-exchange privilege-escalation remote-code-execution
3t 1c updated
medium advisory

M365 Exchange Inbox Rule with Obfuscated Name

This rule detects when a Microsoft Exchange inbox rule is created or modified with a name composed only of special characters, which adversaries may use to evade detection and hide malicious forwarding or deletion rules.

Microsoft 365 +1 cloud saas email exchange defense evasion persistence
2r 2t
high advisory

Microsoft Exchange Server Vulnerability Could Allow Arbitrary Code Execution

A vulnerability in Microsoft Exchange Server allows for arbitrary code execution, potentially enabling attackers to execute malicious JavaScript within a user's browser context to steal data or install malware.

Exchange Server code-execution javascript exchange web-application
2r 1t
medium advisory

CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability

CVE-2026-42897 is a cross-site scripting (XSS) vulnerability in Microsoft Exchange Server that allows an attacker to perform spoofing attacks by injecting malicious scripts into web pages.

PoC Exchange Server +7 xss spoofing exchange
2r 2t 1c 8i updated
high threat

Suspicious Processes Spawned by Microsoft Exchange Worker Process

Detects suspicious processes spawned by the Microsoft Exchange Server worker process (w3wp.exe), potentially indicating exploitation or web shell activity.

exploited Exchange Server initial-access webshell exchange-server windows
2r 2t
medium threat

Microsoft Exchange Server UM Spawning Suspicious Processes

This rule detects suspicious processes spawned by the Microsoft Exchange Server Unified Messaging (UM) service, potentially indicating exploitation of CVE-2021-26857 and leading to unauthorized process execution and system compromise.

exploited Exchange Server exchange initial-access lateral-movement cve-2021-26857 windows
2r 2t 1c
high advisory

Windows Shell Execution from IIS Installation Directory

Detection of command-line tools executing from the IIS installation directory on Windows systems, potentially indicating exploitation of IIS-reliant software like Microsoft Exchange.

Exchange Server +3 iis web-shell command-execution windows
2r 2t
high threat

Suspicious Processes Spawned by Microsoft Exchange Worker Process

The Microsoft Exchange Server worker process (w3wp.exe) spawning command-line interpreters such as cmd.exe or powershell.exe may indicate exploitation of Exchange vulnerabilities or access to a web shell backdoor, leading to unauthorized access and code execution.

exploited Exchange Server exchange webshell initial-access
2r 4t
medium advisory

New ActiveSync Allowed Device Added via PowerShell

The rule detects the use of the Exchange PowerShell cmdlet, Set-CASMailbox, to add a new ActiveSync allowed device, potentially allowing attackers to gain persistent access to sensitive email data by adding unauthorized devices.

Microsoft Defender XDR +4 exchange activesync powershell persistence
2r 3t
high advisory

DNS Kerberos Coercion Attempt Detection

This brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.

PoC Fortinet edge appliances +38 kerberos coercion dns cve-2025-33073
3r 3t 4c 4i updated