New Exploit Method that Bypasses ProxyNotShell Mitigations

Red | Vulnerability Report

A new exploit method has been found in the mitigations of the Microsoft Exchange vulnerability ProxyNotShell URL rewrite that allows for remote code execution (RCE) on compromised servers through Outlook Web Access (OWA). The threat actors responsible for this new exploit have been identified as members of the Play ransomware group.

Reduce real exposure. Not just vulnerability volume.