#proxyshell search results

ProxyShell is still alive in the networks of giant players! 🫡 #ProxyShell #windows #ActiveDirectory #BugBounty

ransomsec's tweet image. ProxyShell is still alive in the networks of giant players! 🫡

#ProxyShell #windows #ActiveDirectory #BugBounty

Vídeo NUEVO ❗️ Ustedes se enteraron de la vulnerabilidad #ProxyShell en #ExcahngeServer? Muchos no y de hecho todavía no han actualizado sus servidores. La Fiscalía de Colombia se vió afectada y te cuento este caso 👇🏻 youtu.be/h-dPwsmBPwI Deja tu me gusta 💙

SoyITPro's tweet image. Vídeo NUEVO ❗️
Ustedes se enteraron de la vulnerabilidad #ProxyShell en #ExcahngeServer? Muchos no y de hecho todavía no han actualizado sus servidores.
La Fiscalía de Colombia se vió afectada y te cuento este caso 👇🏻

youtu.be/h-dPwsmBPwI 

Deja tu me gusta 💙

🚨 vulnerabilidades de Microsoft Exchange siguen siendo explotadas por grupos criminales #ProxyNotShell #ProxyShell #cybersecurity #ciberseguridad

CiberneticaChis's tweet image. 🚨 vulnerabilidades de Microsoft Exchange siguen siendo explotadas por grupos criminales #ProxyNotShell #ProxyShell #cybersecurity #ciberseguridad

🚨 #ProxyLogon and #ProxyShell Pose Ongoing Threats to #Government Mail Servers 🔍 Researchers found ongoing exploitation of these vulnerabilities in #MicrosoftExchange servers, targeting government entities in Asia, Europe, and South America to steal sensitive communications. 🔗…

socradar's tweet image. 🚨 #ProxyLogon and #ProxyShell Pose Ongoing Threats to #Government Mail Servers
🔍 Researchers found ongoing exploitation of these vulnerabilities in #MicrosoftExchange servers, targeting government entities in Asia, Europe, and South America to steal sensitive communications.
🔗…

Microsoft Exchange ProxyShell is being exploited to mine crypto once again #MicrosoftExchange #ProxyShell #Crypto ow.ly/x9xk50MWhOF

Symmetric_Group's tweet image. Microsoft Exchange ProxyShell is being exploited to mine crypto once again
#MicrosoftExchange #ProxyShell #Crypto 
ow.ly/x9xk50MWhOF

Hackers are targeting unpatched Microsoft Exchange servers in 26 countries with JavaScript keyloggers to steal credentials. Read more! thehackernews.com/2025/06/hacker… #CyberSecurity #MicrosoftExchange #ProxyShell #CredentialTheft #ThreatIntelligence #InfoSec

TiltRecruitment's tweet image. Hackers are targeting unpatched Microsoft Exchange servers in 26 countries with JavaScript keyloggers to steal credentials.

Read more! thehackernews.com/2025/06/hacker…

#CyberSecurity #MicrosoftExchange #ProxyShell #CredentialTheft #ThreatIntelligence #InfoSec

Microsoft Exchange ProxyShell flaws exploited in new crypto-mining attack bleepingcomputer.com/news/security/… #Microsoft #Exchange #ProxyShell


Keylogger found on Microsoft Exchange Server steals login credentials globally. Discovered by Positive Technologies, this #Keylogger targets gov't and business logins since 2021. Exploits #ProxyShell vulnerability. #Cybersecurity #MicrosoftExchange

allendevaux's tweet image. Keylogger found on Microsoft Exchange Server steals login credentials globally. Discovered by Positive Technologies, this #Keylogger targets gov't and business logins since 2021. Exploits #ProxyShell vulnerability. #Cybersecurity #MicrosoftExchange

未確認の攻撃者が65台の古いExchangeサーバにキー入力ログ挿入。既知ProxyShell脆弱性悪用し、JavaScriptで送信型/保存型キーロガー仕込み。政府・金融等が標的。古い脆弱Exchangeサーバの放置は致命的。#ExchangeAttack #Keylogger #ProxyShell thehackernews.com/2025/06/hacker…


Top causes of a #ransomware attack: 1. ☠️Exploited Vulnerabilities (36%): Attacks carried out by exploiting vulnerabilities found in devices, often due to lack of diligent patching. #ProxyShell and #Log4Shell vulnerabilities were frequently present in affected assets. 2.…


#CobaltStrike beacon was deployed via a webshell that was planted by exploiting the #ProxyShell vulnerability. This #HsHarada campaign targets healthcare and healthcare-adjacent organizations, and relies on github.com/Tas9er


Hunt identified a server likely exploiting #ProxyLogon & #ProxyShell flaws to gain initial access and steal sensitive communications. This renewed activity has affected government entities across multiple regions, including Asia, Europe, and South America securityonline.info/proxylogon-pro…

securityonline.info

ProxyLogon & ProxyShell Vulnerabilities Back: Gov't Emails Breached

Nearly three years after the notorious ProxyLogon and ProxyShell vulnerabilities caused widespread havoc on Microsoft Exchange servers


This year's #ProxyShell incident was a humbling reminder that no vendor is immune to #cyberattacks. Check out this article that dives into some of the lessons we learned as this vulnerability made its rounds. cpomagazine.com/cyber-security…


#ProxyShell y #ProxyLogon fueron grandes oportunidades para adversarios, es hora de un nuevo set de vulnerabilidades abusadas on-the-wild. Más detalles en @behackerpro behacker.pro/proxynotshell-…


#ProxyShell in 2023 ? (src: @onyphe)


🚨Major Threat Alert: Keylogger Found Lurking in Microsoft Exchange Server - #ProxyShell CVE-2021-34523 CVE-2021-31207 CVE-2021-34473 CVE-2020-1472 Severity: 🔴 High Maturity: 💥 Mainstream fletch.ai/p/proxyshell #CyberSecurity #ThreatIntel #InfoSec


Last time even got banned at #reddit asking some questions including microsoft exchange server . Its not a dumb subject because its one of a very large attack surface ever existing because of its complexity. There are #proxylogon , #proxyshell and ??? more to appear


Hackers are targeting unpatched Microsoft Exchange servers in 26 countries with JavaScript keyloggers to steal credentials. Read more! thehackernews.com/2025/06/hacker… #CyberSecurity #MicrosoftExchange #ProxyShell #CredentialTheft #ThreatIntelligence #InfoSec

TiltRecruitment's tweet image. Hackers are targeting unpatched Microsoft Exchange servers in 26 countries with JavaScript keyloggers to steal credentials.

Read more! thehackernews.com/2025/06/hacker…

#CyberSecurity #MicrosoftExchange #ProxyShell #CredentialTheft #ThreatIntelligence #InfoSec

未確認の攻撃者が65台の古いExchangeサーバにキー入力ログ挿入。既知ProxyShell脆弱性悪用し、JavaScriptで送信型/保存型キーロガー仕込み。政府・金融等が標的。古い脆弱Exchangeサーバの放置は致命的。#ExchangeAttack #Keylogger #ProxyShell thehackernews.com/2025/06/hacker…


🚨 #ProxyLogon and #ProxyShell Pose Ongoing Threats to #Government Mail Servers 🔍 Researchers found ongoing exploitation of these vulnerabilities in #MicrosoftExchange servers, targeting government entities in Asia, Europe, and South America to steal sensitive communications. 🔗…

socradar's tweet image. 🚨 #ProxyLogon and #ProxyShell Pose Ongoing Threats to #Government Mail Servers
🔍 Researchers found ongoing exploitation of these vulnerabilities in #MicrosoftExchange servers, targeting government entities in Asia, Europe, and South America to steal sensitive communications.
🔗…

Hunt identified a server likely exploiting #ProxyLogon & #ProxyShell flaws to gain initial access and steal sensitive communications. This renewed activity has affected government entities across multiple regions, including Asia, Europe, and South America securityonline.info/proxylogon-pro…

securityonline.info

ProxyLogon & ProxyShell Vulnerabilities Back: Gov't Emails Breached

Nearly three years after the notorious ProxyLogon and ProxyShell vulnerabilities caused widespread havoc on Microsoft Exchange servers


Keylogger Malware Deployed Through MS Exchange Server Vulnerabilities in Targeted Attacks #Keylogger #keylogging #ProxyShell #logonaspx #MicrosoftExchangeServer #clkLgn ptsecurity.com/ww-en/analytic…


🚨Major Threat Alert: Keylogger Found Lurking in Microsoft Exchange Server - #ProxyShell CVE-2021-34523 CVE-2021-31207 CVE-2021-34473 CVE-2020-1472 Severity: 🔴 High Maturity: 💥 Mainstream fletch.ai/p/proxyshell #CyberSecurity #ThreatIntel #InfoSec


Keylogger found on Microsoft Exchange Server steals login credentials globally. Discovered by Positive Technologies, this #Keylogger targets gov't and business logins since 2021. Exploits #ProxyShell vulnerability. #Cybersecurity #MicrosoftExchange

allendevaux's tweet image. Keylogger found on Microsoft Exchange Server steals login credentials globally. Discovered by Positive Technologies, this #Keylogger targets gov't and business logins since 2021. Exploits #ProxyShell vulnerability. #Cybersecurity #MicrosoftExchange

Alternate tactic being used in #ProxyShell: attacker modified IIS "MSExchangeOWAAppPool" app pool by adding additional virtual directory to "/owa" with path "/auth/类/hxxxy". Webshell located in C:\ProgramData\COM1\hxxxy. Check your configs when hunting!

DaveKleinatland's tweet image. Alternate tactic being used in #ProxyShell: attacker modified IIS "MSExchangeOWAAppPool" app pool by adding additional virtual directory to "/owa" with path "/auth/类/hxxxy". Webshell located in C:\ProgramData\COM1\hxxxy. Check your configs when hunting!

🚨 Ahora, más de 384.000 correos (67 GB) del Ministerio de Justicia de Chile 🇨🇱 han sido filtrados a raíz de un ataque a la plataforma Microsoft Exchange, al parecer, utilizando las mismas vulnerabilidades explotadas por #Guacamaya. #ProxyLogon #ProxyShell 🥹

1ZRR4H's tweet image. 🚨 Ahora, más de 384.000 correos (67 GB) del Ministerio de Justicia de Chile 🇨🇱 han sido filtrados a raíz de un ataque a la plataforma Microsoft Exchange, al parecer, utilizando las mismas vulnerabilidades explotadas por #Guacamaya.

#ProxyLogon #ProxyShell 🥹
1ZRR4H's tweet image. 🚨 Ahora, más de 384.000 correos (67 GB) del Ministerio de Justicia de Chile 🇨🇱 han sido filtrados a raíz de un ataque a la plataforma Microsoft Exchange, al parecer, utilizando las mismas vulnerabilidades explotadas por #Guacamaya.

#ProxyLogon #ProxyShell 🥹

I have written an @pdnuclei rule to detect the compromise of the Proxyshell vulnerability. I'll test a little more before committing. Very happy with the result 🚀 #proxyshell #CVE-2021-34473 #CTI

johnk3r's tweet image. I have written an @pdnuclei  rule to detect the compromise of the Proxyshell vulnerability. I'll test a little more before committing. Very happy with the result 🚀

#proxyshell #CVE-2021-34473 #CTI

Sigma rules to detect #Exchange #ProxyShell exploitation attempts I'll improve the rules tomorrow with actual PoCs (someone was so kind and offered to share his PoC with me) HTTP log github.com/SigmaHQ/sigma/… Process Creation github.com/SigmaHQ/sigma/…

cyb3rops's tweet image. Sigma rules to detect #Exchange #ProxyShell exploitation attempts

I'll improve the rules tomorrow with actual PoCs (someone was so kind and offered to share his PoC with me)

HTTP log 
github.com/SigmaHQ/sigma/…

Process Creation
github.com/SigmaHQ/sigma/…
cyb3rops's tweet image. Sigma rules to detect #Exchange #ProxyShell exploitation attempts

I'll improve the rules tomorrow with actual PoCs (someone was so kind and offered to share his PoC with me)

HTTP log 
github.com/SigmaHQ/sigma/…

Process Creation
github.com/SigmaHQ/sigma/…

Turns out you don't need a valid email address to exploit #ProxyShell. You can just ask the server for them: github.com/dmaasland/prox…

donnymaasland's tweet image. Turns out you don't need a valid email address to exploit #ProxyShell. You can just ask the server for them:

github.com/dmaasland/prox…

Some cheeky #ProxyShell shenanigans in a discovered webshell -- the BQPQ variable looks like enough gibberish to be consider Base64 at first glance, but it's just a pool of characters to pull from and index the letters to build out the "unsafe" keyword for the eval function.

_JohnHammond's tweet image. Some cheeky #ProxyShell shenanigans in a discovered webshell -- the BQPQ variable looks like enough gibberish to be consider Base64 at first glance, but it's just a pool of characters to pull from and index the letters to build out the "unsafe" keyword for the eval function.

Casi 2.000 servidores de Exchange hackeados con el exploit #ProxyShell j.mp/2XPzbpX

SeguInfo's tweet image. Casi 2.000 servidores de Exchange hackeados con el exploit #ProxyShell j.mp/2XPzbpX

Keep your Exchange servers safe this weekend. @HuntressLabs has seen 140+ webshells across 1900+ unpatched boxes in 48hrs. Impacted orgs thus far include building mfgs, seafood processors, industrial machinery, auto repair shops, a small residential airport and more. #ProxyShell

KyleHanslovan's tweet image. Keep your Exchange servers safe this weekend. @HuntressLabs has seen 140+ webshells across 1900+ unpatched boxes in 48hrs. Impacted orgs thus far include building mfgs, seafood processors, industrial machinery, auto repair shops, a small residential airport and more. #ProxyShell

Such an understatement right now. #ProxyShell

KyleHanslovan's tweet image. Such an understatement right now. #ProxyShell

Another good thing to look out for, is webshells saved as attachments in people's mailboxes. They are encoded, but can be decoded with this simple script: gist.github.com/rxwx/b5a8ef0cd… #ProxyShell

buffaloverflow's tweet image. Another good thing to look out for, is webshells saved as attachments in people's mailboxes. They are encoded, but can be decoded with this simple script:

gist.github.com/rxwx/b5a8ef0cd…

#ProxyShell
buffaloverflow's tweet image. Another good thing to look out for, is webshells saved as attachments in people's mailboxes. They are encoded, but can be decoded with this simple script:

gist.github.com/rxwx/b5a8ef0cd…

#ProxyShell

ATIO Group 🇲🇽 Exchange comprometido vía #ProxyShell Deben realizar análisis de seguridad ASAP! ⚠️ cc: @ATIOGroup

1ZRR4H's tweet image. ATIO Group 🇲🇽
Exchange comprometido vía #ProxyShell 

Deben realizar análisis de seguridad ASAP! ⚠️

cc: @ATIOGroup

Added the "normal" RCE to the PoC for #ProxyShell. Code isn't the prettiest, but gets the job done: github.com/dmaasland/prox…

donnymaasland's tweet image. Added the "normal" RCE to the PoC for #ProxyShell. Code isn't the prettiest, but gets the job done: 

github.com/dmaasland/prox…

I've found a way to do RCE with just this PoC and the "New-ExchangeCertificate" cmdlet. See: youtu.be/HEqt7ew7cGU (Don't worry about the erros, my lab is slow). Command I used here: gist.github.com/dmaasland/0720…. Drive responsibly :)

donnymaasland's tweet image. I've found a way to do RCE with just this PoC and the "New-ExchangeCertificate" cmdlet. See: youtu.be/HEqt7ew7cGU (Don't worry about the erros, my lab is slow). 

Command I used here: gist.github.com/dmaasland/0720….

Drive responsibly :)
donnymaasland's tweet image. I've found a way to do RCE with just this PoC and the "New-ExchangeCertificate" cmdlet. See: youtu.be/HEqt7ew7cGU (Don't worry about the erros, my lab is slow). 

Command I used here: gist.github.com/dmaasland/0720….

Drive responsibly :)


Secretaría de Seguridad del Estado de México 🇲🇽 MS Exchange comprometido vía #ProxyShell Peligro inminente, deben realizar análisis de seguridad al servidor y las cuentas lo más pronto posible! ⚠️ cc: @SS_Edomex

1ZRR4H's tweet image. Secretaría de Seguridad del Estado de México 🇲🇽
MS Exchange comprometido vía #ProxyShell 

Peligro inminente, deben realizar análisis de seguridad al servidor y las cuentas lo más pronto posible! ⚠️ 

cc: @SS_Edomex

La banda de ransomware LockFile "weaponiza" #ProxyShell y #PetitPotam j.mp/3ja9tEC

SeguInfo's tweet image. La banda de ransomware LockFile "weaponiza" #ProxyShell y #PetitPotam j.mp/3ja9tEC

For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently THOR Lite nextron-systems.com/thor-lite/ YARA rules github.com/Neo23x0/signat… github.com/Neo23x0/signat…

cyb3rops's tweet image. For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner

We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently

THOR Lite
nextron-systems.com/thor-lite/

YARA rules
github.com/Neo23x0/signat…
github.com/Neo23x0/signat…
cyb3rops's tweet image. For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner

We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently

THOR Lite
nextron-systems.com/thor-lite/

YARA rules
github.com/Neo23x0/signat…
github.com/Neo23x0/signat…
cyb3rops's tweet image. For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner

We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently

THOR Lite
nextron-systems.com/thor-lite/

YARA rules
github.com/Neo23x0/signat…
github.com/Neo23x0/signat…
cyb3rops's tweet image. For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner

We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently

THOR Lite
nextron-systems.com/thor-lite/

YARA rules
github.com/Neo23x0/signat…
github.com/Neo23x0/signat…

Loading...

Something went wrong.


Something went wrong.


United States Trends