Smile On Fridays secured coverage in WIRED for Red Canary

Microsoft warned the world that a Chinese state-sponsored hacking group called Hafnium had infected what would turn out to be tens of thousands of Microsoft Exchange servers in a weeks-long hacking blitz. While Microsoft soon released a patch, not every victim updated their systems, and hundreds of servers remained exposed. A little over a month later, the Department of Justice has now revealed, the FBI took extraordinary steps to protect those still at risk.

Court documents unsealed this week reveal that the FBI obtained a warrant to copy and delete so-called web shells—essentially a foothold into a system that hackers can use to send remote commands or malware—from hundreds of Hafnium victims. While the operation seems straightforward on a technical level, it establishes a precedent that manages to be at once both controversial and refreshingly restrained.

