
Lynx Ransomware
Lynx Ransomware is rapidly expanding, targeting organizations across North America and Europe with data theft and double extortion, backed by a growing network of skilled affiliates.

In late September 2022 Microsoft released information relating to 2 previously unknown zero-day vulnerabilities collectively known as "ProxyNotShell" affecting Microsoft Exchange. These vulnerabilities were noted by security researchers to be actively exploited in the wild. The two vulnerabilities (CVE-2022-41040 and CVE-2022-41082) are known to impact Microsoft Exchange Server 2013, 2016, and 2019. ProxyNotShell, according to Microsoft, is two vulnerabilities with "... the first vulnerability, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, while the second, identified as CVE-2022-41082, allows remote code execution (RCE) when PowerShell is accessible to the attacker." Microsoft does note that successful exploitation does require authentication to trigger either vulnerability.
Owing to the fact that the vulnerabilities associated with ProxyNotShell are being actively exploited in the wild, Cyborg Security has released several hunt packages to the community in order to detect behaviors known to be associated with the attack. Sign up for a free Community HUNTER Account to get exclusive access to these hunt packages today!
Get the Free Hunt Packages!
Check Out Other Emerging Threats >

Lynx Ransomware is rapidly expanding, targeting organizations across North America and Europe with data theft and double extortion, backed by a growing network of skilled affiliates.

Threat actors are increasingly using methods to circumvent multifactor authentication, which poses a risk of account takeover. Here’s a briefing on some types of attacks and defenses to put in place.

mommy Access Broker is enabling access-as-a-service operations through detailed intrusion guides and compromised credentials, and Intel 471 has released reporting and Hunt Packages to support threat hunting and detection.
Stay informed with our weekly executive update, sending you the latest news and timely data on the threats, risks, and regulations affecting your organization.