Cyber Security Weekly Podcast

Episode 252 - Microsoft Exchange Hack and advice for Threat Hunting - MySecTV Takeaway


Listen Later

Following Microsoft’s news about Hafnium, the Australian Cyber Security Centre (ACSC) advises organisations using Microsoft Exchange to urgently patch the following Common Vulnerabilities and Exposures (CVEs):
CVE-2021-26855 – server-side request forgery (SSRF) vulnerability in Exchange.CVE-2021-26857 – insecure deserialization vulnerability in the Unified Messaging service.CVE-2021-26858 – post-authentication arbitrary file write vulnerability in Exchange.CVE-2021-27065 – post-authentication arbitrary file write vulnerability in Exchange.If successfully exploited, these CVEs would allow an unauthenticated attacker to write files and execute code with elevated privileges on the underlying Microsoft Windows operating system.
A large number of Australian organisations are yet to patch vulnerable versions of Microsoft Exchange, leaving them vulnerable to compromise. The ACSC is encouraging these organisations to do so urgently.
We cross to the US and speak with Mat Gangwer, Senior Director, Sophos Managed Threat Response and review the Microsoft Exchange hack and threat hunting advice.
Full article, including updated ESET research: https://australiancybersecuritymagazine.com.au/microsoft-outlook-hack-and-advice-for-threat-hunting/ (https://australiancybersecuritymagazine.com.au/microsoft-outlook-hack-and-advice-for-threat-hunting/)
#Exchangehack (https://www.youtube.com/hashtag/exchangehack)​ #microsoft (https://www.youtube.com/hashtag/microsoft)​ #cybersecurity (https://www.youtube.com/hashtag/cybersecurity)​ #cyberbreach (https://www.youtube.com/hashtag/cyberbreach)​ #exchange (https://www.youtube.com/hashtag/exchange)​ #CVE (https://www.youtube.com/hashtag/cve)​ #Sophos (https://www.youtube.com/hashtag/sophos)
Recorded Friday 12 March 2020 - video version is available here https://mysecuritymarketplace.com/av-media/microsoft-exchange-hack-and-advice-for-threat-hunting/ (https://mysecuritymarketplace.com/av-media/microsoft-exchange-hack-and-advice-for-threat-hunting/)
...more
View all episodesView all episodes
Download on the App Store

Cyber Security Weekly PodcastBy MySecurity Media

  • 3.9
  • 3.9
  • 3.9
  • 3.9
  • 3.9

3.9

19 ratings


More shows like Cyber Security Weekly Podcast

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,979 Listeners

Risky Business by Patrick Gray

Risky Business

365 Listeners

Future Tense by ABC listen

Future Tense

73 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

366 Listeners

Politics Now by ABC listen

Politics Now

104 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

312 Listeners

Click Here by Recorded Future News

Click Here

413 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,879 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

166 Listeners

If You're Listening by ABC listen

If You're Listening

313 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

A Bit of Optimism by Simon Sinek

A Bit of Optimism

2,186 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

127 Listeners

The TED AI Show by TED

The TED AI Show

46 Listeners