• Skip to main content
  • Skip to primary sidebar
  • Skip to footer

Technologous - Managed IT Solutions Bryan/College Station

  • Home
  • About
    • Areas We Serve
    • Our Leadership
      • Chris Dawson
      • Ian Soares
  • IT Services
    • Managed IT
    • Support IT
    • Cloud IT
  • Blog
  • Request a Consultation
  • Contact
You are here: Home / Blog / Hackers Attacking Exchange Servers In New Warning From Microsoft

Hackers Attacking Exchange Servers In New Warning From Microsoft

Recently, Microsoft’s Defender ATP Research Team issued guidance relating to defending against attacks that target Exchange servers.

They are coming under increasing attack based on the latest Microsoft statistics, which show a marked increase in the use of web shells on on-premises Exchange servers.

The company is currently tracking multiple ongoing attacks, some of which are using fileless techniques. That adds an additional layer of complexity when it comes to detecting and preventing attacks.

According to the advisory issued by Microsoft, the recent campaigns: 

“…exploit a remote code execution vulnerability affecting the underlying Internet Information Service (ISS) component of a target Exchange server.

…This is an attacker’s dream: directly landing on a server and, if the server has misconfigured access levels, gain system privileges…In many cases, after attackers gain access to an Exchange server, what follows is the deployment of web shell into one of the many web-accessible paths on the server.”

Web shells are versatile, highly customizable tools hackers deploy on compromised servers to not only gain but also to maintain their access. They are used to remotely execute arbitrary commands and code, deliver a wide range of malicious payloads, and to move laterally within the network to other devices.

Microsoft said that the most recent spate of attacks are specifically targeting vulnerabilities like CVE-2020-0688. If there’s a silver lining to be found, it lies in that there are already security patches available that protect against the most commonly used exploits in the recent string of attacks.

Unfortunately, those patches are unevenly applied across the Enterprise landscape, which leaves a significant percentage of corporate Exchange servers vulnerable to attack. Based on the latest company statistics released at the time this piece was written, although the patch has been available for some weeks, 82.5 percent of all Exchange servers were as yet unprotected. If yours is among that number, the fix is easy.

July 3, 2020 Filed Under: Blog Tagged With: Attacks, exchange servers, Hackers, Microsoft

Primary Sidebar

GET OUR BLOG IN YOUR EMAIL!

Archives

  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • April 2020
  • March 2020
  • February 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • August 2018

Tags

adobe android App Apple attack Attacks Breach Browser Chrome Dark Web Data Database Data Breach Email Facebook Firefox gmail Google Google Chrome government hacker Hackers information Intel iOS iPhone malware Microsoft Microsoft edge Microsoft Windows 10 office 365 pandemic Password Passwords patch Phishing Phishing emails ransomeware Ransomware security Update Vulnerability Wifi Windows Windows 10

Footer

Contact Us

Address: 3091 University Drive, Unit 210, Bryan, Texas 77802
Phone: 979-217-1226

Our Blog

  • Apple Updates Fix Security Flaws on Most Devices March 19, 2021
  • Sendgrid Uses Zoom Invites to Steal Credentials March 18, 2021
  • Browser Wars Heat Up With Microsoft Edge Boosting Speeds March 18, 2021
  • Microsoft’s Exchange Prevents Phishing And Ransomware March 17, 2021
  • Ransomware Attackers Demand 20 Million From U.S. Kia Motors March 12, 2021

Search

Follow Us

  • Facebook
  • Home
  • About
  • Resources
  • Contact
  • Our Leadership
  • Why Choose Us?
  • IT Services
  • Request a Consultation

Copyright © 2021| All Rights Reserved | Powered By Technologous, LLC | Log in