The Stack
"Publishing security advisories for such critical issues with such limited information only serves to hurt defenders and threat hunters"
Attacks appear to be "linked to legacy credential use during migrations from Gen 6 to Gen 7 firewalls"
"Once on the network, the attackers don't waste time. Their actions are a mix of automated scripts for speed and hands-on-keyboard activity"
"If IIS is restarted without manually removing malicious module entries from applicationHost.config and web.config files, any malicious modules will persist and reload..."