Btw Microsoft, CERTs and a bunch of other orgs are also using Shodan to find out who is exposed. We already had all the data to determine vulnerability before the announcement was made so enterprise customers could search their local Shodan database for affected systems. And we've been sending out notifications as well.
Lovin' my membership.
The question that comes to mind is: to what extent did Threat Actors have unfettered access to security bulletins?
There is no easy solution to the issue. Thank you for bringing this up.
> On March 2, Microsoft released emergency security updates to plug four security holes in Exchange Server ...
> ... [Volexity] first saw attackers quietly exploiting the Exchange bugs on Jan. 6, 2021, ...
If it still wasn't apparent by then, though, I would have thought that this line should've cleared things up:
> We’ve worked on dozens of cases so far where web shells were put on the victim system back on Feb. 28 [before Microsoft announced its patches], ...*