Flow
Flow
TriniTuner.com  |  Latest Event:  

Forums

Hundreds of thousands of MS Exchange email servers hacked, patch now!

this is how we do it.......

Moderator: 3ne2nr Mods

redmanjp
TriniTuner 24-7
Posts: 17670
Joined: September 22nd, 2009, 11:01 pm
Contact:

Hundreds of thousands of MS Exchange email servers hacked, patch now!

Postby redmanjp » March 6th, 2021, 3:01 pm

https://appleinsider.com/articles/21/03/06/microsoft-exchange-server-hack-affects-over-30000-us-organizations
Ongoing & enormous Microsoft Exchange server hack hits 30,000 US groups
Malcolm Owen By Malcolm Owen | Mar 06, 2021

The Hafnium hacking group in China has allegedly hacked at least 30,000 organizations in the United States using Microsoft Exchange Server, with the group said to have increased its activity in the wake of the hack's initial reports.

On Wednesday, Microsoft disclosed evidence that "Hafnium," a Chinese hacking group, was attacking servers in the United States and around the world using Microsoft Exchange Server. Microsoft also released emergency security patches to plug four security holes affecting Exchange Server version 2013 to 2019, which were used by the group.

By Saturday, hints of the extent of the hacking spree indicated it was wide-ranging and major in scale.

According to a source of Reuters on Friday, the attack had affected more than 20,000 US organizations. However, two anonymous cybersecurity experts who briefed US national security advisors on the attack told KrebsOnSecurity the number is far higher, in excess of 30,000 organizations.

Furthermore, despite the release of patches, the experts claim the group have stepped up their attacks, in a bid to gain access to unpatched Exchange servers. On a global scale, the attack is said to have affected "hundreds of thousands" of servers. :shock:

While unconfirmed, it appears that the mass hack is at a larger scale than that of SolarWinds. It is believed more than 18,000 organizations could have been affected by that network management software hack.

Even in the event organizations applied the patch, there is a chance they may still be affected. As part of the hack, the group leaves a "web shell" installed, a hacking tool accessible from a browser that provides administrative access to servers.

Organizations that apply the patches can prevent the hack from occurring, but the web shell could still be present on the system if they were hacked previously.

It is claimed victims still running the web shell include thousands of U.S. entities, including financial institutions, charities and non-profits, and the operations of emergency services.

"Even if you patched the same day Microsoft published its patches, there's still a high chance there is a web shell on your server," said security firm Volexity president Steven Adair. "The truth is, if you're running Exchange and you haven't patched this yet, there's a very high chance that your organization is already compromised."

The scale of the hacks has led to the US Cybersecurity & Infrastructure Security Agency (CISA) to issue an emergency directive ordering federal departments and agencies to update their Microsoft Exchange servers or take the servers offline. White House press secretary has also warned the vulnerabilities "could have far-reaching impacts, with a fear there could be a "large number of victims."

AppleInsider has affiliate partnerships and may earn commission on products purchased through affiliate links. These partnerships do not influence our editorial content.


User avatar
teems1
punchin NOS
Posts: 3448
Joined: March 15th, 2007, 4:44 pm

Re: Hundreds of thousands of MS Exchange email servers hacked, patch now!

Postby teems1 » March 6th, 2021, 7:30 pm

If you haven't migrated to O365 now might be the time to do it.

User avatar
Keyser Soze
I LUV THIS PLACE
Posts: 928
Joined: January 7th, 2005, 9:48 am

Re: Hundreds of thousands of MS Exchange email servers hacked, patch now!

Postby Keyser Soze » March 6th, 2021, 7:36 pm

teems1 wrote:If you haven't migrated to O365 now might be the time to do it.


endorsed!
saved me headaches when we did.
still have nightmares of the all nighters during the christmas season some years ago when we had to rebuild....augh

User avatar
DMan7
punchin NOS
Posts: 4488
Joined: February 2nd, 2021, 5:17 pm

Re: Hundreds of thousands of MS Exchange email servers hacked, patch now!

Postby DMan7 » March 6th, 2021, 7:51 pm

People still run their own Exchange Servers now? I thought by now most people use virtual servers in Azure to get this email server done?

redmanjp
TriniTuner 24-7
Posts: 17670
Joined: September 22nd, 2009, 11:01 pm
Contact:

Re: Hundreds of thousands of MS Exchange email servers hacked, patch now!

Postby redmanjp » March 6th, 2021, 9:51 pm

even if u have 365 if u also have on premise servers i think u are affected

User avatar
st7
3ne2nr Toppa Toppa
Posts: 5340
Joined: October 23rd, 2006, 1:13 am

Re: Hundreds of thousands of MS Exchange email servers hacked, patch now!

Postby st7 » March 7th, 2021, 7:12 pm

DMan7 wrote:People still run their own Exchange Servers now? I thought by now most people use virtual servers in Azure to get this email server done?


it have some companies who dont trust 'the cloud'

Fadakartel
Street 2NR
Posts: 78
Joined: March 3rd, 2013, 6:17 pm

Re: Hundreds of thousands of MS Exchange email servers hacked, patch now!

Postby Fadakartel » March 8th, 2021, 2:04 am

DMan7 wrote:People still run their own Exchange Servers now? I thought by now most people use virtual servers in Azure to get this email server done?


Yeah people do run local exchange, in banking the cloud is a major issue with PCI, GDPR etc.

Some places in the world you need central bank approvals before migrating anything to the cloud. I`m facing this currently.

redmanjp
TriniTuner 24-7
Posts: 17670
Joined: September 22nd, 2009, 11:01 pm
Contact:

Re: Hundreds of thousands of MS Exchange email servers hacked, patch now!

Postby redmanjp » March 8th, 2021, 3:34 pm

wonder if anyone locally was hacked

User avatar
st7
3ne2nr Toppa Toppa
Posts: 5340
Joined: October 23rd, 2006, 1:13 am

Re: Hundreds of thousands of MS Exchange email servers hacked, patch now!

Postby st7 » March 8th, 2021, 10:42 pm

anyone check up on Tatil yet?

Advertisement

Return to “Ole talk and more Ole talk”

Who is online

Users browsing this forum: No registered users and 16 guests