-
Do you still patch on premises Exchange servers?
Do you still patch a Microsoft Exchange server in your network? If you do, heads up. There is
limited/targeted attackswidespread attacks underway. Microsoft has released patches for it. While they say “Exchange online is not impacted”… my guess is that it’s already patched and/or mitigated for the issue.What’s interesting to me is that the attackers are coming FROM the United States. It’s like the SolarWinds attacks, they aren’t coming from outside the USA, but inside. Thus geo blocking no longer works to keep the bad guys out.
Note this is no longer “limited attacks”. Many small businesses have been impacted as well.
Microsoft has detected multiple 0-day exploits being used to attack on-premises versions of Microsoft Exchange Server in limited and targeted attacks. Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to HAFNIUM. https://t.co/tdsYGFICML
— Microsoft Threat Intelligence (@MsftSecIntel) March 2, 2021