Trustwave SpiderLabs Uncovers Ov3r_Stealer Malware Spread via Phishing and Facebook Advertising. Learn More

Trustwave SpiderLabs Uncovers Ov3r_Stealer Malware Spread via Phishing and Facebook Advertising. Learn More

Services
Capture
Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

twi-managed-portal-color
Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

twi-briefcase-color-svg
Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

tw-laptop-data
Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

twi-database-color-svg
Database Security

Prevent unauthorized access and exceed compliance requirements.

twi-email-color-svg
Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

tw-officer
Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

tw-network
Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Solutions
BY TOPIC
Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Partners
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats

Mitigate Microsoft Exchange Server Attacks

We’re here 24x7x365 to help protect you against new emerging threats such as the recent Microsoft Exchange Vulnerability attacks.

What are the Microsoft Exchange Server attacks?


Microsoft announced four critical zero-day Microsoft Exchange Server vulnerabilities on March 2. HAFNIUM, an advanced threat actor group assessed to be state-sponsored, and other threat actors across the globe have been attacking organizations by exploiting these vulnerabilities. Hundreds of thousands of organizations are believed to be affected by these attacks. If exploited, an organization can suffer a complete email system takeover, a potential installation of malware to grant long-term access to environments, or lateral movement inside the organization by the attacker.

CISO's Corner: The Microsoft Exchange Server Attacks Should Change Your Security Mindset

Hundreds of thousands of organizations are reported to have been affected by the Microsoft Exchange Server attacks. HAFNIUM, an advanced threat actor group assessed to be state-sponsored, and numerous other threat actors across the globe have been attacking organizations by exploiting critical zero-day vulnerabilities in Microsoft Exchange Servers.

 
TRUSTWAVE BLOG

HAFNIUM, China Chopper and ASP.NET Runtime

The recent Microsoft Exchange Server zero-day exploits have seen tens of thousands of organizations compromised by HAFNIUM and numerous other threat actor groups. Working closely with our customers across the globe, we have quickly been able to identify and isolate attributes of those attacks – particularly the China Chopper web shell that is being uploaded to compromised IIS servers.

 
SPIDERLABS BLOG

Trustwave's Action Response to the Microsoft Exchange Server Zero-Day Vulnerabilities and Attacks

A Microsoft report indicated that the named vulnerabilities were being exploited in the wild by a new threat actor group Microsoft named HAFNIUM. According to Microsoft, HAFNIUM is a group assessed to be state-sponsored and operating out of China, based on observed victimology, tactics and procedures.

 


SPIDERLABS BLOG

Trustwave Can Help


tw-magnifying-glass
Digital Forensics and Incident Response (DFIR)

Trustwave DFIR services provide forensic and incident response services with human intelligence and unparalleled technology across four delivery regions. We have 24x7x365 direct on-call forensic, threat intelligence, and incident response capabilities that integrate with SOC operations. Trustwave can perform a deep investigation on your environment to find malicious activity.

tw-threat-management
Managed Detection and Response (MDR)

Leveraging our cloud-based cybersecurity platform Trustwave Fusion and industry-leading global threat intelligence capabilities from Trustwave SpiderLabs®, we integrate our services with your security environment and program. We provide you complete visibility across endpoint, network and cloud so that we can find threats quickly and eradicate them for you seamlessly.

twi-radar-alt-color
Threat Hunting

Our human-driven approach employs Trustwave SpiderLabs® threat hunting experts with defense mindsets and hands-on experience conducting hundreds of threat hunts and investigations. When we find something, we work with you to respond with action.

tw-firewall
Penetration Testing

Trustwave can perform all types of security testing, including network scans, standard and custom penetration tests, and retests to help you get a comprehensive understanding of your risk exposure and where your vulnerabilities reside.