Exchange vulnerability may have led to attack on NetStandard MSP, researchers say
MSP NetStandard had to take down cloud-based MyAppsAnywhere environment until further notice.
Stay updated with breaking news from Server Software Component. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
MSP NetStandard had to take down cloud-based MyAppsAnywhere environment until further notice.
On 2021-02-28, we noticed that the vulnerabilities were used by other threat actors, starting with Tick and quickly joined by LuckyMouse, Calypso and the Winnti Group. This suggests that multiple threat actors gained access to the details of the vulnerabilities before the release of the patch, which means we can discard the possibility that they built an exploit by reverse engineering Microsoft updates. Finally, the day after the release of the patch, we started to see many more threat actors (including Tonto Team and Mikroceen) scanning and compromising Exchange servers en masse. Interesting...