ProxyLogon (Mar 2021): Exchange Server Zero-Days Exploited at Massive Scale
On March 2, 2021, Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, collectively known as...
Insights
Articles in Microsoft 365.
On March 2, 2021, Microsoft released emergency patches for four zero-day vulnerabilities in on-premises Microsoft Exchange Server, collectively known as...
On-premises Exchange servers were exploited repeatedly from 2021 to 2022. If you've moved mailboxes to Exchange Online, you may be able to retire your last...
Exchange Server exploitation typically results in web shells and suspicious processes spawned by IIS worker processes. These are the key detections.
The short version: In 2021, attackers exploited flaws in Microsoft Exchange email servers that companies ran themselves, compromising tens of thousands of...
In January 2021, email security company Mimecast disclosed that a certificate it used to authenticate certain products to Microsoft 365 Exchange Online had...
Third-party applications connected to Exchange Online can read, send or manage mail across your organization. Here is how to review them.
A compromised third-party integration can access your tenant with the app's permissions. These detections focus on unusual behavior by third-party apps.
The short version: In 2021, Mimecast — an email security company — disclosed that a digital certificate its products used to connect to customers' Microsoft...
At Microsoft Ignite in September 2020, Microsoft reorganized its security products under a single brand: Microsoft Defender. The change reflected its...
Microsoft's security product names have changed many times. Here is a practical map of the Microsoft Defender family — what each product does and how to...
Owning Microsoft Defender licenses isn't the same as being protected. Use this checklist to onboard the Defender XDR products properly.
The short version: Many companies pay for Microsoft 365 E5 or similar licenses that include a full suite of security tools — and use only part of it....
In July 2020, Microsoft warned about a rise in consent phishing (also called illicit consent grant) campaigns, many using COVID-19 themes. Instead of...
Malicious OAuth apps can read mail and files without a password. Here is how to find and remove them in Microsoft 365.
Illicit consent grants give attackers persistent access to Microsoft 365 data. Detecting them quickly is essential because password resets don't remove them.
The short version: In 2020, attackers began tricking employees into clicking "Accept" on a Microsoft permission screen for a fake app. The employee signs in...
In early 2020, as remote work exploded, "Zoom-bombing" entered the vocabulary: uninvited people joined online meetings and classrooms to disrupt them with...
Microsoft Teams meeting policies decide who can join, present and record. Here is how to tighten them without making meetings painful.
Meeting disruption and eavesdropping are rare, but when they happen in sensitive meetings the impact is high. These detections help you spot unusual meeting...
The short version: In 2020, uninvited strangers began crashing online meetings — "Zoom-bombing." It was a wake-up call: video meetings had become as...
In March 2020, the COVID-19 pandemic sent much of the global workforce home almost overnight. Microsoft Teams usage exploded as organizations rushed to keep...
Teams sprawl and forgotten guest access create real security risk. Here is how to put lightweight governance in place without slowing collaboration.
Guest accounts and broad Teams access can quietly expose sensitive data. These detections highlight risky guest activity and sharing.
The short version: When COVID-19 sent everyone home in 2020, companies opened up collaboration tools as fast as possible. Many never tightened them again....