Technology Today

Multiple nation-state hackers have begun exploiting a vulnerability in Microsoft Exchange email servers that was recently patched.The UK-based cybersecurity firm Volexity first spotted the vulnerability being exploited in the wild but the firm did not name any of the hacking groups involved.The vulnerability, tracked under the identifier CVE-2020-0688, was patched by Microsoft last month.
If exploited though, the remote code execution vulnerability could be used to read all of an organization's emails as it gives attackers full control of a Microsoft Exchange email server.While Microsoft has already patched the vulnerability, a technical report from the Zero-Day Initiative, who first reported the bug to the company, provided extensive details on the bug and how it works.
This report served as a roadmap for security researchers who used the information it contained to create proof-of-concept exploits to prepare their own servers for possible attacks.Following the release of Zero-Day Initiative's report, hacker groups began to scan the internet for vulnerable Exchange servers which they could launch attacks against in the future.In a new blog post, Volexity revealed that cybercriminals' scans for vulnerable Exchange servers have turned into actual attacks, saying:Volexity has observed multiple APT actors exploiting or attempting to exploit on-premise Exchange servers.
In some cases the attackers appear to have been waiting for an opportunity to strike with credentials that had otherwise been of no use.
Many organizations employ two-factor authentication (2FA) to protect their VPN, e-mail, etc., limiting what an attacker can do with a compromised password.
This vulnerability gives attackers the ability to gain access to a significant asset within an organization with a simple user credential or old service account.Thankfully though, the vulnerability in Exchange is not easy to exploit and to do so, hackers need to have the credentials for an email account on the server they're trying to attack.
This means that less advanced hackers will be unable to do so while nation-state hackers have the resources to exploit the vulnerability.All Microsoft Exchange servers are considered vulnerable to these attacks including versions that have reached their end-of-life (EoL).
Organizations should apply the latest patch as soon as possible and if they're running an EoL version, they should consider updating to a newer Exchange version.Via ZDNet





Unlimited Portal Access + Monthly Magazine - 12 issues


Contribute US to Start Broadcasting - It's Voluntary!


ADVERTISE


Merchandise (Peace Series)

 


Leading 20 pieces of tech Brits miss the most - consisting of corded phones and movie video cameras


Everyone utilizing Chrome put on red alert and informed to clear browsing data immediately


Rare deal that rivals Amazon sale sees Samsung Galaxy Smartwatch plummet to £39


Get a free Samsung Galaxy Watch - tech editor shares where to discover it


Fortnite down RECAP: Epic Games release declaration as video game continues to be offline


Top Tech: Sky launches UK's 'fastest broadband' with big 5Gbps fibre upgrade


Virgin Media users alerted they deal with new streaming block - examine your television and act now


All UK WhatsApp users put on alert and provided with immediate pointer this week


Gtech's 'perfect' cordless vacuum package is £& pound; 200 off and makes cleaning 'a lot simpler'


TOWIE's Pete Wicks succumbs to 'fake' Wimbledon influencer who tricked him


Sky summertime sale cuts cost of family essentials but Virgin has something much better


UK Fire television Stick users will be obstructed from popular streaming app on this exact date


Nifty Samsung code gets Galaxy fans this mobile for less


Sky TV block as brand-new crackdown interrupts UK homes from viewing content totally free


Sky's biggest-ever conserving on Gigafast broadband cuts £& pound; 96 off the ultimate upgrade


Google is fixing a major issue with your Gmail inbox, and free upgrade is coming soon


Top Tech: 5 Amazon-rivalling deals from Apple, Samsung, Shark and more


Amazon Prime Day: Favourite tech gizmos and home appliances we actually use and love


Consumers can get an Echo Pop speaker for less than ₤ 6 if they do one easy thing


Sky is dispensing a huge upgrade, however just if your postcode is on this list


Amazon slashes ₤ 450 off Shark self-emptying robotic vacuum in mega Prime Day offer


Newest Kindle hits lowest ever cost in Amazon Prime Day deal with over ₤ 100 off


Samsung unveils new Galaxy, and it makes your current Android phone appearance extremely inferior


Simply hours remain on Virgin Media's complimentary 4K TV deal - act quickly


Everyone with an Android phone placed on red alert as massive new threat validated


The 'finest' smart device of 2025 confirmed - has the iPhone or Android come out on top


Amazon's best Apple deals for Prime Day consisting of iPhone, iPad and AirPods


Tech professional warns 'never state yes' to 3 questions from callers you don't recognise


Millions of Brits 'forced to function as online security guards' for elderly family members


Leading Tech: Virgin Media's totally free television giveaway ends quickly as 48-hour countdown begins


All Amazon Prime users put on high alert - you need to follow 4 new rules today


Amazon gives you 3 reasons to ditch your Fire TV Stick and try something new this week


Apple fans rush for 22% off AirPods Pro 2 as Amazon Prime Day kicks off


Paramount+ drops to £3.99 in half price sale ending this week


Amazon is handing out free Echo speakers this week and here's how to get yours