HC3 TLP Analyst Note: Microsoft Exchange Server Zero-Days Actively Exploited March 3, 2021

On March 2, 2021, Microsoft being actively exploited in targeted attacks. These flaws affect Microsoft Exchange Server versions 2013, 2016, and 2019. Exchange Online (O365) is not affected. Microsoft has labeled the group that is actively attacking vulnerable Exchange servers HAFNIUM who, according to them is Other researchers have identified other threat actors, believed to be China-based, to be exploiting these vulnerabilities as well. View the entire report under key resources.