Beginning in January 2021, Mandiant Managed Defense observed multiple instances of abuse of Microsoft Exchange Server within at least one client environment. The observed activity included creation...
Read moreFour Microsoft Exchange Zero-Days Exploited by China
March 4 2021Microsoft has issued an emergency Microsoft Exchange patch to fix four zero-day vulnerabilities currently being exploited by China. EDITED TO ADD (3/12): Exchange Online is not affected.
Read moreChinese Hackers Stole an NSA Windows Exploit in 2014
March 4 2021
Check Point has evidence that (probably government affiliated) Chinese hackers stole and cloned an NSA Windows hacking tool years before (probably government affiliated) Russian hackers stole and then...
Read moreTwelve-Year-Old Vulnerability Found in Windows Defender
February 24 2021
Researchers found, and Microsoft has patched, a vulnerability in Windows Defender that has been around for twelve years. There is no evidence that anyone has used the vulnerability...
Read morePatch now to stop hackers blindly crashing your Windows computers
February 10 2021Patch early, patch often. In fact, patch now if you haven't already. Here's why.
Read moreSVR Attacks on Microsoft 365
January 21 2021
FireEye is reporting the current known tactics that the SVR used to compromise Microsoft 365 cloud data as part of its SolarWinds operation:
Mandiant has observed UNC2452 and other...
Read more
Malicious Domain in SolarWinds Hack Turned into ‘Killswitch’
December 16 2020A key malicious domain name used to control potentially thousands of computer systems compromised via the months-long breach at network monitoring software vendor SolarWinds was commandeered by security experts...
Read moreSolarWinds Hack Could Affect 18K Customers
December 15 2020The still-unfolding breach at network management software firm SolarWinds may have resulted in malicious code being pushed to nearly 18,000 customers, the company said in a legal filing on...
Read moreU.S. Treasury, Commerce Depts. Hacked Through SolarWinds Compromise
December 14 2020Communications at the U.S. Treasury and Commerce Departments were reportedly compromised by a supply chain attack on SolarWinds, a security vendor that helps the federal government and a range...
Read moreUS Cyber Command and Microsoft Are Both Disrupting TrickBot
October 15 2020
Earlier this month, we learned that someone is disrupting the TrickBot botnet network.
Over the past 10 days, someone has been launching a series of coordinated attacks designed to...
Read more

Recent Comments