Robuta

https://www.techtarget.com/healthtechsecurity/news/366595321/DOJ-FBI-Removed-Web-Shells-From-Exploited-Microsoft-Exchange-Servers
A court-authorized FBI effort removed malicious web shells from network environments compromised by exploits of four zero-day vulnerabilities in Microsoft...
web shellsmicrosoft exchangedojfbiremoved
https://thehackernews.com/2025/10/cisa-and-nsa-issue-urgent-guidance-to.html
CISA and NSA warn of WSUS and Exchange attacks, urging immediate patching and zero trust adoption.
cisansaissueurgentguidance
https://securityaffairs.com/141451/security/microsoft-exchange-servers-patch.html
Microsoft warns customers to patch their Exchange servers because attackers always look to exploit unpatched installs.
patch managementexchange serverscrucialprotectmicrosoft
https://cloud.google.com/blog/topics/threat-intelligence/pst-want-shell-proxyshell-exploiting-microsoft-exchange-servers
microsoft exchangepstwantshellexploiting
https://cloud.google.com/blog/topics/threat-intelligence/pst-want-shell-proxyshell-exploiting-microsoft-exchange-servers/
microsoft exchangepstwantshellexploiting
https://www.techtarget.com/searchsecurity/news/252513468/Sophos-discovers-new-attack-targeting-Exchange-Servers
Sophos published a report on a new attack against Microsoft Exchange Server that used the Squirrelwaffle malware.
exchange serverssophosdiscoversnewattack
https://therecord.media/chinese-apt-targeted-exchange-servers-with-four-zero-days-microsoft-says
Microsoft released emergency security updates today to patch four zero-day vulnerabilities that were exploited by a Chinese APT group.
exchange serverszero daysmicrosoftchineseapt
https://www.windowscentral.com/new-ransomware-called-lockfile-targets-microsoft-exchange-servers
A new ransomware attack known as LockFile is targeting Microsoft Exchange servers. Security researchers disagree on how attackers are gaining access to servers.
microsoft exchangewindows centralnewransomwarecalled
https://thehackernews.com/2023/01/microsoft-urges-customers-to-secure-on.html?m=0
Microsoft urges customers keep their servers up to date and implement additional security measures, such as enabling Windows Extended Protection.
exchange serversmicrosofturgescustomerssecure
https://www.nextgov.com/cybersecurity/2021/03/cisa-orders-immediate-action-vulnerabilities-microsoft-exchange-servers/172438/
All agencies must report their status to CISA by noon on March 5.
immediate actionmicrosoft exchangecisaordersvulnerabilities
https://www.helpnetsecurity.com/2021/03/15/microsoft-exchange-exploit/
Microsoft Exchange servers around the world are still getting compromised via the exploit leveraged by 10 or more APTs and a ransomware gang.
exchange serversattacksescalatemicrosoftinvestigates