ProxyShell is still alive in the networks of giant players! 🫡 #ProxyShell #windows #ActiveDirectory #BugBounty

ransomsec's tweet image. ProxyShell is still alive in the networks of giant players! 🫡

#ProxyShell #windows #ActiveDirectory #BugBounty

Vídeo NUEVO ❗️ Ustedes se enteraron de la vulnerabilidad #ProxyShell en #ExcahngeServer? Muchos no y de hecho todavía no han actualizado sus servidores. La Fiscalía de Colombia se vió afectada y te cuento este caso 👇🏻 youtu.be/h-dPwsmBPwI Deja tu me gusta 💙

SoyITPro's tweet image. Vídeo NUEVO ❗️
Ustedes se enteraron de la vulnerabilidad #ProxyShell en #ExcahngeServer? Muchos no y de hecho todavía no han actualizado sus servidores.
La Fiscalía de Colombia se vió afectada y te cuento este caso 👇🏻

youtu.be/h-dPwsmBPwI 

Deja tu me gusta 💙

🚨 #ProxyLogon and #ProxyShell Pose Ongoing Threats to #Government Mail Servers 🔍 Researchers found ongoing exploitation of these vulnerabilities in #MicrosoftExchange servers, targeting government entities in Asia, Europe, and South America to steal sensitive communications. 🔗…

socradar's tweet image. 🚨 #ProxyLogon and #ProxyShell Pose Ongoing Threats to #Government Mail Servers
🔍 Researchers found ongoing exploitation of these vulnerabilities in #MicrosoftExchange servers, targeting government entities in Asia, Europe, and South America to steal sensitive communications.
🔗…

🚨 vulnerabilidades de Microsoft Exchange siguen siendo explotadas por grupos criminales #ProxyNotShell #ProxyShell #cybersecurity #ciberseguridad

CiberneticaChis's tweet image. 🚨 vulnerabilidades de Microsoft Exchange siguen siendo explotadas por grupos criminales #ProxyNotShell #ProxyShell #cybersecurity #ciberseguridad

Microsoft Exchange ProxyShell is being exploited to mine crypto once again #MicrosoftExchange #ProxyShell #Crypto ow.ly/x9xk50MWhOF

Symmetric_Group's tweet image. Microsoft Exchange ProxyShell is being exploited to mine crypto once again
#MicrosoftExchange #ProxyShell #Crypto 
ow.ly/x9xk50MWhOF

Hackers are targeting unpatched Microsoft Exchange servers in 26 countries with JavaScript keyloggers to steal credentials. Read more! thehackernews.com/2025/06/hacker… #CyberSecurity #MicrosoftExchange #ProxyShell #CredentialTheft #ThreatIntelligence #InfoSec

TiltRecruitment's tweet image. Hackers are targeting unpatched Microsoft Exchange servers in 26 countries with JavaScript keyloggers to steal credentials.

Read more! thehackernews.com/2025/06/hacker…

#CyberSecurity #MicrosoftExchange #ProxyShell #CredentialTheft #ThreatIntelligence #InfoSec

Microsoft Exchange ProxyShell flaws exploited in new crypto-mining attack bleepingcomputer.com/news/security/… #Microsoft #Exchange #ProxyShell


Keylogger found on Microsoft Exchange Server steals login credentials globally. Discovered by Positive Technologies, this #Keylogger targets gov't and business logins since 2021. Exploits #ProxyShell vulnerability. #Cybersecurity #MicrosoftExchange

allendevaux's tweet image. Keylogger found on Microsoft Exchange Server steals login credentials globally. Discovered by Positive Technologies, this #Keylogger targets gov't and business logins since 2021. Exploits #ProxyShell vulnerability. #Cybersecurity #MicrosoftExchange

#CobaltStrike beacon was deployed via a webshell that was planted by exploiting the #ProxyShell vulnerability. This #HsHarada campaign targets healthcare and healthcare-adjacent organizations, and relies on github.com/Tas9er


This year's #ProxyShell incident was a humbling reminder that no vendor is immune to #cyberattacks. Check out this article that dives into some of the lessons we learned as this vulnerability made its rounds. cpomagazine.com/cyber-security…


Top causes of a #ransomware attack: 1. ☠️Exploited Vulnerabilities (36%): Attacks carried out by exploiting vulnerabilities found in devices, often due to lack of diligent patching. #ProxyShell and #Log4Shell vulnerabilities were frequently present in affected assets. 2.…


Hunt identified a server likely exploiting #ProxyLogon & #ProxyShell flaws to gain initial access and steal sensitive communications. This renewed activity has affected government entities across multiple regions, including Asia, Europe, and South America securityonline.info/proxylogon-pro…


未確認の攻撃者が65台の古いExchangeサーバにキー入力ログ挿入。既知ProxyShell脆弱性悪用し、JavaScriptで送信型/保存型キーロガー仕込み。政府・金融等が標的。古い脆弱Exchangeサーバの放置は致命的。#ExchangeAttack #Keylogger #ProxyShell thehackernews.com/2025/06/hacker…


#ProxyShell y #ProxyLogon fueron grandes oportunidades para adversarios, es hora de un nuevo set de vulnerabilidades abusadas on-the-wild. Más detalles en @behackerpro behacker.pro/proxynotshell-…


🚨Major Threat Alert: Keylogger Found Lurking in Microsoft Exchange Server - #ProxyShell CVE-2021-34523 CVE-2021-31207 CVE-2021-34473 CVE-2020-1472 Severity: 🔴 High Maturity: 💥 Mainstream fletch.ai/p/proxyshell #CyberSecurity #ThreatIntel #InfoSec


Hackers are targeting unpatched Microsoft Exchange servers in 26 countries with JavaScript keyloggers to steal credentials. Read more! thehackernews.com/2025/06/hacker… #CyberSecurity #MicrosoftExchange #ProxyShell #CredentialTheft #ThreatIntelligence #InfoSec

TiltRecruitment's tweet image. Hackers are targeting unpatched Microsoft Exchange servers in 26 countries with JavaScript keyloggers to steal credentials.

Read more! thehackernews.com/2025/06/hacker…

#CyberSecurity #MicrosoftExchange #ProxyShell #CredentialTheft #ThreatIntelligence #InfoSec

未確認の攻撃者が65台の古いExchangeサーバにキー入力ログ挿入。既知ProxyShell脆弱性悪用し、JavaScriptで送信型/保存型キーロガー仕込み。政府・金融等が標的。古い脆弱Exchangeサーバの放置は致命的。#ExchangeAttack #Keylogger #ProxyShell thehackernews.com/2025/06/hacker…


🚨 #ProxyLogon and #ProxyShell Pose Ongoing Threats to #Government Mail Servers 🔍 Researchers found ongoing exploitation of these vulnerabilities in #MicrosoftExchange servers, targeting government entities in Asia, Europe, and South America to steal sensitive communications. 🔗…

socradar's tweet image. 🚨 #ProxyLogon and #ProxyShell Pose Ongoing Threats to #Government Mail Servers
🔍 Researchers found ongoing exploitation of these vulnerabilities in #MicrosoftExchange servers, targeting government entities in Asia, Europe, and South America to steal sensitive communications.
🔗…

Hunt identified a server likely exploiting #ProxyLogon & #ProxyShell flaws to gain initial access and steal sensitive communications. This renewed activity has affected government entities across multiple regions, including Asia, Europe, and South America securityonline.info/proxylogon-pro…


🚨Major Threat Alert: Keylogger Found Lurking in Microsoft Exchange Server - #ProxyShell CVE-2021-34523 CVE-2021-31207 CVE-2021-34473 CVE-2020-1472 Severity: 🔴 High Maturity: 💥 Mainstream fletch.ai/p/proxyshell #CyberSecurity #ThreatIntel #InfoSec


Keylogger found on Microsoft Exchange Server steals login credentials globally. Discovered by Positive Technologies, this #Keylogger targets gov't and business logins since 2021. Exploits #ProxyShell vulnerability. #Cybersecurity #MicrosoftExchange

allendevaux's tweet image. Keylogger found on Microsoft Exchange Server steals login credentials globally. Discovered by Positive Technologies, this #Keylogger targets gov't and business logins since 2021. Exploits #ProxyShell vulnerability. #Cybersecurity #MicrosoftExchange

Alternate tactic being used in #ProxyShell: attacker modified IIS "MSExchangeOWAAppPool" app pool by adding additional virtual directory to "/owa" with path "/auth/类/hxxxy". Webshell located in C:\ProgramData\COM1\hxxxy. Check your configs when hunting!

DaveKleinatland's tweet image. Alternate tactic being used in #ProxyShell: attacker modified IIS "MSExchangeOWAAppPool" app pool by adding additional virtual directory to "/owa" with path "/auth/类/hxxxy". Webshell located in C:\ProgramData\COM1\hxxxy. Check your configs when hunting!

🚨 Ahora, más de 384.000 correos (67 GB) del Ministerio de Justicia de Chile 🇨🇱 han sido filtrados a raíz de un ataque a la plataforma Microsoft Exchange, al parecer, utilizando las mismas vulnerabilidades explotadas por #Guacamaya. #ProxyLogon #ProxyShell 🥹

1ZRR4H's tweet image. 🚨 Ahora, más de 384.000 correos (67 GB) del Ministerio de Justicia de Chile 🇨🇱 han sido filtrados a raíz de un ataque a la plataforma Microsoft Exchange, al parecer, utilizando las mismas vulnerabilidades explotadas por #Guacamaya.

#ProxyLogon #ProxyShell 🥹
1ZRR4H's tweet image. 🚨 Ahora, más de 384.000 correos (67 GB) del Ministerio de Justicia de Chile 🇨🇱 han sido filtrados a raíz de un ataque a la plataforma Microsoft Exchange, al parecer, utilizando las mismas vulnerabilidades explotadas por #Guacamaya.

#ProxyLogon #ProxyShell 🥹

ProxyShell is still alive in the networks of giant players! 🫡 #ProxyShell #windows #ActiveDirectory #BugBounty

ransomsec's tweet image. ProxyShell is still alive in the networks of giant players! 🫡

#ProxyShell #windows #ActiveDirectory #BugBounty

I have written an @pdnuclei rule to detect the compromise of the Proxyshell vulnerability. I'll test a little more before committing. Very happy with the result 🚀 #proxyshell #CVE-2021-34473 #CTI

johnk3r's tweet image. I have written an @pdnuclei  rule to detect the compromise of the Proxyshell vulnerability. I'll test a little more before committing. Very happy with the result 🚀

#proxyshell #CVE-2021-34473 #CTI

Sigma rules to detect #Exchange #ProxyShell exploitation attempts I'll improve the rules tomorrow with actual PoCs (someone was so kind and offered to share his PoC with me) HTTP log github.com/SigmaHQ/sigma/… Process Creation github.com/SigmaHQ/sigma/…

cyb3rops's tweet image. Sigma rules to detect #Exchange #ProxyShell exploitation attempts

I'll improve the rules tomorrow with actual PoCs (someone was so kind and offered to share his PoC with me)

HTTP log 
github.com/SigmaHQ/sigma/…

Process Creation
github.com/SigmaHQ/sigma/…
cyb3rops's tweet image. Sigma rules to detect #Exchange #ProxyShell exploitation attempts

I'll improve the rules tomorrow with actual PoCs (someone was so kind and offered to share his PoC with me)

HTTP log 
github.com/SigmaHQ/sigma/…

Process Creation
github.com/SigmaHQ/sigma/…

Casi 2.000 servidores de Exchange hackeados con el exploit #ProxyShell j.mp/2XPzbpX

SeguInfo's tweet image. Casi 2.000 servidores de Exchange hackeados con el exploit #ProxyShell j.mp/2XPzbpX

🚨 Sitios del gobierno mexicano 🇲🇽 comprometidos vía #ProxyShell [2021-11-06 - LIVE #Webshells] El sitio de la Secretaría de Seguridad del Estado fue reportado hace 77 días atrás. 💡 Exploit ha sido utilizado por Conti, LockFile y Babuk #Ransomware REF: bleepingcomputer.com/news/security/…

1ZRR4H's tweet image. 🚨 Sitios del gobierno mexicano 🇲🇽 comprometidos vía #ProxyShell [2021-11-06 - LIVE #Webshells]

El sitio de la Secretaría de Seguridad del Estado fue reportado hace 77 días atrás.

💡 Exploit ha sido utilizado por Conti, LockFile y Babuk #Ransomware

REF: bleepingcomputer.com/news/security/…
1ZRR4H's tweet image. 🚨 Sitios del gobierno mexicano 🇲🇽 comprometidos vía #ProxyShell [2021-11-06 - LIVE #Webshells]

El sitio de la Secretaría de Seguridad del Estado fue reportado hace 77 días atrás.

💡 Exploit ha sido utilizado por Conti, LockFile y Babuk #Ransomware

REF: bleepingcomputer.com/news/security/…

Another good thing to look out for, is webshells saved as attachments in people's mailboxes. They are encoded, but can be decoded with this simple script: gist.github.com/rxwx/b5a8ef0cd… #ProxyShell

buffaloverflow's tweet image. Another good thing to look out for, is webshells saved as attachments in people's mailboxes. They are encoded, but can be decoded with this simple script:

gist.github.com/rxwx/b5a8ef0cd…

#ProxyShell
buffaloverflow's tweet image. Another good thing to look out for, is webshells saved as attachments in people's mailboxes. They are encoded, but can be decoded with this simple script:

gist.github.com/rxwx/b5a8ef0cd…

#ProxyShell

For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently THOR Lite nextron-systems.com/thor-lite/ YARA rules github.com/Neo23x0/signat… github.com/Neo23x0/signat…

cyb3rops's tweet image. For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner

We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently

THOR Lite
nextron-systems.com/thor-lite/

YARA rules
github.com/Neo23x0/signat…
github.com/Neo23x0/signat…
cyb3rops's tweet image. For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner

We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently

THOR Lite
nextron-systems.com/thor-lite/

YARA rules
github.com/Neo23x0/signat…
github.com/Neo23x0/signat…
cyb3rops's tweet image. For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner

We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently

THOR Lite
nextron-systems.com/thor-lite/

YARA rules
github.com/Neo23x0/signat…
github.com/Neo23x0/signat…
cyb3rops's tweet image. For a compromise assessment of #Exchange servers I recommend using our free THOR Lite scanner

We've added all rules & IOCs relevant to #ProxyShell exploitation & update them frequently

THOR Lite
nextron-systems.com/thor-lite/

YARA rules
github.com/Neo23x0/signat…
github.com/Neo23x0/signat…

Turns out you don't need a valid email address to exploit #ProxyShell. You can just ask the server for them: github.com/dmaasland/prox…

donnymaasland's tweet image. Turns out you don't need a valid email address to exploit #ProxyShell. You can just ask the server for them:

github.com/dmaasland/prox…

Breaking: Attackers are actively abusing the latest line of Microsoft Exchange vulnerabilities to install a backdoor for later access and post-exploitation. #ProxyShell hubs.ly/H0VGydM0

HuntressLabs's tweet image. Breaking: Attackers are actively abusing the latest line of Microsoft Exchange vulnerabilities to install a backdoor for later access and post-exploitation. #ProxyShell hubs.ly/H0VGydM0

Need a quick run-down of how the #ProxyShell exploit differs from #ProxyLogon? We've recapped what you need to know on our blog. Happy patching! hubs.ly/H0W1QNb0 #cybersecurity #MicrosoftExchange

HuntressLabs's tweet image. Need a quick run-down of how the #ProxyShell exploit differs from #ProxyLogon?

We've recapped what you need to know on our blog. Happy patching! hubs.ly/H0W1QNb0

#cybersecurity #MicrosoftExchange

Added the "normal" RCE to the PoC for #ProxyShell. Code isn't the prettiest, but gets the job done: github.com/dmaasland/prox…

donnymaasland's tweet image. Added the "normal" RCE to the PoC for #ProxyShell. Code isn't the prettiest, but gets the job done: 

github.com/dmaasland/prox…

I've found a way to do RCE with just this PoC and the "New-ExchangeCertificate" cmdlet. See: youtu.be/HEqt7ew7cGU (Don't worry about the erros, my lab is slow). Command I used here: gist.github.com/dmaasland/0720…. Drive responsibly :)

donnymaasland's tweet image. I've found a way to do RCE with just this PoC and the "New-ExchangeCertificate" cmdlet. See: youtu.be/HEqt7ew7cGU (Don't worry about the erros, my lab is slow). 

Command I used here: gist.github.com/dmaasland/0720….

Drive responsibly :)
donnymaasland's tweet image. I've found a way to do RCE with just this PoC and the "New-ExchangeCertificate" cmdlet. See: youtu.be/HEqt7ew7cGU (Don't worry about the erros, my lab is slow). 

Command I used here: gist.github.com/dmaasland/0720….

Drive responsibly :)


Loading...

Something went wrong.


Something went wrong.


United States Trends