Source: Microsoft, Bleeping Computer Ransomware-wielding attackers have begun to exploit a serious proxy-logon flaw in unpatched versions of Microsoft Exchange running on premises, Microsoft reports. Hackers have exploited the flaw to access vulnerable servers, crypto-lock files and demand a ransom from victims in return for the promise of a decryption tool. News of the attack campaign follows Microsoft on March 2 issuing emergency patches to fix four zero-day flaws in Microsoft Exchange, which is one of the most widely used pieces of IT infrastructure in the world. "Because we are aware of active exploits of related vulnerabilities in the wild," Microsoft said in its March 2021 Exchange Server Security Updates alert, which it continues to update, "our recommendation is to install these updates immediately to protect against these attacks."