Technology Today

Multiple nation-state hackers have begun exploiting a vulnerability in Microsoft Exchange email servers that was recently patched.The UK-based cybersecurity firm Volexity first spotted the vulnerability being exploited in the wild but the firm did not name any of the hacking groups involved.The vulnerability, tracked under the identifier CVE-2020-0688, was patched by Microsoft last month.
If exploited though, the remote code execution vulnerability could be used to read all of an organization's emails as it gives attackers full control of a Microsoft Exchange email server.While Microsoft has already patched the vulnerability, a technical report from the Zero-Day Initiative, who first reported the bug to the company, provided extensive details on the bug and how it works.
This report served as a roadmap for security researchers who used the information it contained to create proof-of-concept exploits to prepare their own servers for possible attacks.Following the release of Zero-Day Initiative's report, hacker groups began to scan the internet for vulnerable Exchange servers which they could launch attacks against in the future.In a new blog post, Volexity revealed that cybercriminals' scans for vulnerable Exchange servers have turned into actual attacks, saying:Volexity has observed multiple APT actors exploiting or attempting to exploit on-premise Exchange servers.
In some cases the attackers appear to have been waiting for an opportunity to strike with credentials that had otherwise been of no use.
Many organizations employ two-factor authentication (2FA) to protect their VPN, e-mail, etc., limiting what an attacker can do with a compromised password.
This vulnerability gives attackers the ability to gain access to a significant asset within an organization with a simple user credential or old service account.Thankfully though, the vulnerability in Exchange is not easy to exploit and to do so, hackers need to have the credentials for an email account on the server they're trying to attack.
This means that less advanced hackers will be unable to do so while nation-state hackers have the resources to exploit the vulnerability.All Microsoft Exchange servers are considered vulnerable to these attacks including versions that have reached their end-of-life (EoL).
Organizations should apply the latest patch as soon as possible and if they're running an EoL version, they should consider updating to a newer Exchange version.Via ZDNet





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Top Tech: Samsung sale cuts Galaxy S25 to record low price as new Edge model drops


Samsung Galaxy S25 Edge pre-orders with official prices and double storage giveaway


'This 30% off power bank has a genius feature that makes it my everyday pick'


Your iPhone just got an important free upgrade from Apple - check your settings now


Your Galaxy S25 just got beaten by a radically new smartphone from Samsung


Gtech cordless vacuum that leaves floors 'pristine' has £100 off


Sky TV and broadband deal is cheapest yet - but it ends in days


All WhatsApp users placed on red alert - delete 'dangerous' new message now


Watch out Sky - brand-new UK rival includes more TV functions and is totally free to enjoy


You may be sorry for buying Samsung's Galaxy S25 after seeing what's coming this week


'Modelling is a human endeavour': Models push back rising of AI in style


Virgin Media issues crucial Wi-Fi recommendations - 5 things you 'need to do' today


'I got an AirTag for the cheapest ever price by stacking a deal most don't know about'


Amazon beats Samsung with ₤ 211 discount on The Frame clever television


Biggest ever UK landline switch off confirmed and your home could be on this list


Samsung will give shoppers up to £1000 if they ditch their old TV


Argos' surprise iPhone sale could encourage fans to update as £& pound; 200 is cut from rate


LG takes on Samsung with 50% television discount rate throughout uncommon sale


Worrying new WhatsApp warning issued and ignoring it could see you banned


Sky dishes Phone 16 at 'least expensive ever' cost and rare Apple offer is 'offering quickly'


'Apple AirTag and Samsung SmartTag drop in price - I don't go on a flight without one'


Amazon shoppers state these earphones more affordable than AirPods are 'the best' for physical fitness


Get £40 off Elgato stream deck that speeds up workflow in Amazon's surprise tech sale


Disregard streaming on Spotify, the cassette gamer returns and is way much better than before


Amazon reveals hi-tech robotics that could change big numbers of warehouse workers


All Android users placed on red alert - you must check your settings 'immediately'


Amazon Tech Week Sale: All details as Apple watches and Dyson fans drop in price


Free Amazon upgrade may convince you to ditch your Fire TV Stick for good


Last chance to get £150 off Samsung phone as rare discount ends in hours


Apple fans can pick up an iPhone 16 Pro for less in cost-splitting offer at Sky


Forget the Galaxy S25, Samsung confirms something 'light years ahead' is coming quickly


Broadband providers will pay you up to £300 to switch to a cheaper broadband deal


'I had a skydive at 14,000 feet, forgot one essential thing and the amazing took place'


Sky unveils major update to TV and broadband plan that Virgin and BT can't match


Going screen-free for a week urged by expert as they issue stark health warning


WhatsApp verifies immediate 24-hour due date - you could be obstructed from chats tonight