ProxyLogon is a vulnerability tracked by ThreatCluster, appearing in 11 threat clusters built from 12 intelligence report mentions.
ProxyLogon is a vulnerability tracked across 11 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed October 29, 2025; most recent activity June 25, 2026.
The China-aligned threat group SHADOW-EARTH-053 has been exploiting unpatched Microsoft Exchange and IIS server vulnerabilities, specifically the ProxyLogon vulnerability chain, to conduct cyberespionage. This group has…
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to…
Microsoft has disclosed a critical vulnerability, CVE-2026-42897, affecting on-premises Exchange Server versions 2016, 2019, and Subscription Edition. This zero-day flaw allows attackers to execute arbitrary JavaScript…
The Congressional Budget Office (CBO) confirmed it was hacked, potentially exposing sensitive government data. The agency has implemented new security measures and is investigating the incident, which may involve…
ToddyCat, a cyber espionage group, has been targeting Microsoft Exchange servers since December 2020. The group initially exploited an unidentified vulnerability but significantly ramped up its operations in February…
In 2025, the number of known exploited vulnerabilities in CISA's KEV catalog increased by 20%, with 245 new vulnerabilities added. However, research from Miggo Security indicates that the catalog may only represent 12%…
The Congressional Budget Office (CBO) confirmed on November 6, 2025, that it was hacked, potentially exposing sensitive government data. The breach is believed to be linked to a foreign actor, and the CBO has taken…
Germany's infosec office (BSI) reported that 92 percent of Exchange servers in the country are still operating on out-of-support software. This situation follows Microsoft's termination of support for Exchange versions…
ProxyLogon is a vulnerability tracked by ThreatCluster, appearing in 11 threat clusters built from 12 intelligence report mentions.
The most recent intelligence report mentioning ProxyLogon on ThreatCluster is dated June 25, 2026. Activity was first observed October 29, 2025, giving a tracked span from then to June 25, 2026.
Across ThreatCluster reporting, ProxyLogon most frequently co-occurs with APT41, Earth Alux, Earth Estries, FamousSparrow, GhostEmperor, among 12 tracked related entities.
The most significant recent cluster is “SHADOW-EARTH-053 Exploits Microsoft Exchange Vulnerabilities in Asia” (2 articles · Updated May 5, 2026). ProxyLogon appears across 11 threat clusters in total, listed above with sources.
ProxyLogon appears in 12 intelligence report mentions across 11 deduplicated threat clusters, aggregated from 17,000+ monitored sources.