RSS
Threat Research
Exchange Server
featured
ProxyShell
Sophos X-Ops
ssrf
Two Exchange Server vulns veer dangerously close to ProxyShell
October 3, 2022
active adversary
Active Adversary Report
cve-2021-31207
cve-2021-34473
cve-2021-34523
ProxyLogon
Security Operations
Web shells
Active Adversary Playbook 2022 Insights: Web Shells
June 22, 2022
Artifacts
Attack Tools
cobalt strike
Cryptomining
cyberattacks
cyberthreats
dwell time
Exploit
initial access broker
malware delivery system
MITRE
Ransomware
ransomware as a service
Sophos Rapid Response
vulnerability
The Active Adversary Playbook 2022
June 7, 2022
Bazar
Conti
Karma
Conti and Karma actors attack healthcare provider at same time through ProxyShell exploits
February 28, 2022
email security
Exchange vulnerability
fraud
malspam
Squirrelwaffle
Vulnerable Exchange server hit by Squirrelwaffle and financial fraud
February 15, 2022
malware
MTR
Rapid Response
Sophos XDR
Rapid Response: The Squirrelwaffle Incident Guide
Conti affiliates use ProxyShell Exchange exploit in ransomware attacks
September 3, 2021
SophosLabs Uncut
LockFile
LockFile ransomware’s box of tricks: intermittent encryption and evasion
August 27, 2021
Microsoft Exchange
ProxyShell vulnerabilities in Microsoft Exchange: What to do
August 23, 2021