Microsoft says China-backed hackers are exploiting Exchange zero-days

Discussion in 'other security issues & news' started by ronjor, Mar 2, 2021.

Thread Status:
Not open for further replies.
  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    178,145
    Location:
    Texas
    Zack Whittaker@zackwhittaker / 2:39 PM CST•March 2, 2021
     
  2. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    Cyber has moved to center of national security strategy.

    President’s national security adviser urges Americans to patch a newly discovered vulnerability. IIRC This is a first. Didn’t happen in NotPetya, or more recently in SolarWinds.

    "We are closely tracking Microsoft’s emergency patch for previously unknown vulnerabilities in Exchange Server software and reports of potential compromises of U.S. think tanks and defense industrial base entities. We encourage network owners to patch ASAP: https://msrc-blog.microsoft.com/2021/03/02/mul"

    https://twitter.com/JakeSullivan46/status/1367660450855477256
     
  3. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,613
    I patched my server the day the patch was released. Did not see any sign of being compromised after looking at the Exchange logs etc.
     
  4. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    178,145
    Location:
    Texas
    At Least 30,000 U.S. Organizations Newly Hacked Via Holes in Microsoft’s Email Software
    https://krebsonsecurity.com/2021/03...acked-via-holes-in-microsofts-email-software/
     
  5. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,467
    Location:
    Among the gum trees
    White House fears significant number of organisations caught in Microsoft hack
    https://www.abc.net.au/news/2021-03...ficant-hack-microsoft-exchange-email/13223508
     
  6. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    178,145
    Location:
    Texas
    Microsoft IOC Detection Tool for Exchange Server Vulnerabilities
     
  7. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "Four new hacking groups have joined an ongoing offensive against Microsoft’s email servers

    Chinese hackers targeting Microsoft Exchange servers were joined by a feeding frenzy of other adversaries this week.

    A Chinese government-linked hacking campaign revealed by Microsoft this week has ramped up rapidly. At least four other distinct hacking groups are now attacking critical flaws in Microsoft’s email software in a cyber campaign the US government describes as 'widespread domestic and international exploitation' with the potential to impact hundreds of thousands of victims worldwide..."

    https://www.technologyreview.com/2021/03/06/1020442/four-new-hacking-groups-microsoft-email-servers/
     
  8. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    178,145
    Location:
    Texas
    Thread is closed for comments.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.