FeedVulnerabilityChina-Aligned SHADOW-EARTH-053 Exploits Exchange Servers to ...
VulnerabilityCyber Security News
8.0CRITICAL

China-Aligned SHADOW-EARTH-053 Exploits Exchange Servers to Deploy ShadowPad Malware

📅 5 May 2026 at 15:35 UTC📰 Cyber Security NewsView original source ↗
China-Aligned SHADOW-EARTH-053 Exploits Exchange Servers to Deploy ShadowPad Malware

A China-aligned threat group tracked as SHADOW-EARTH-053 has been exploiting unpatched Microsoft Exchange Server vulnerabilities to conduct cyberespionage against government and defense-linked targets across Asia and beyond. The group’s activity dates back to at least December 2024, with campaigns targeting at least eight countries, including government ministries, defense contractors, IT consulting firms, and transportation organizations […] The post China-Aligned SHADOW-EARTH-053 Exploits Exchange Servers to Deploy ShadowPad Malware appeared first on Cyber Security News.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A China-aligned threat group, SHADOW-EARTH-053, has been exploiting unpatched Microsoft Exchange Server vulnerabilities since at least December 2024 to conduct cyberespionage against government and defense-linked targets across Asia and beyond. The group's campaigns target multiple countries, including government ministries, defense contractors, IT consulting firms, and transportation organizations.

⚙️Technical Details
Affected Systems
Microsoft Exchange Servers
Attack Vectors
unpatched vulnerabilities
💥Impact Assessment
Severity: High
Who Is at Risk
Government ministries, defense contractors, IT consulting firms, and transportation organizations across Asia and beyond
🛡️Recommended Actions
1Ensure Microsoft Exchange Servers are patched with the latest security updates
2Implement regular vulnerability scans for unpatched vulnerabilities
3Monitor logs for suspicious activity related to Microsoft Exchange Servers
📦Affected Products
Microsoft Exchange Server

Read the full article

This is a curated summary. The complete article is available at Cyber Security News.

Read on Cyber Security News
← Back to feed