Are you looking for IT folks to assist you and your business? Email me at Alex dot Moen at ZNWS dot com
Here is what the Cybersecurity & Infrastructure Security Agency is saying business leaders and IT should do: https://us-cert.cisa.gov/remediating-...
If you haven't heard already, it has been uncovered that Microsoft Exchange has been actively exploited and that at least 30,000 organizations in trouble.
First, what is Microsoft Exchange?
You can think of Microsoft Exchange as the backend system for handling emails. If you have Outlook, that is the frontend. Microsoft Exchange is either on your server, or run through Microsoft 365 and Microsoft's servers, or perhaps through a 3rd party vendor who has it on their servers.
What happened with the Microsoft Exchange hack?
4 exploits have been uncovered, and these 4 hacks line up with each other in such a way that can be really bad. To make matters worse, this was first reported in early January 2021 and has even been patch recently, but that just plugs the holes and doesn't stop the potential loss of control that's already happened.
Essentially, with these 4 particular exploits, what seems to be a Chinese state sponsored group of hackers have likely already put into a bunch of organization's web servers what's called a webshell, which pretty much is a backdoor to still get full access and control of anything email related even after a patch. Which means, the patch won't stop the exploits from happening, it just stops others from potentially following the same exploits if they didn't already have their foot in the door.
Unfortunately, the patches for these exploits themselves point towards where the hack occurred, which is likely to have lots of other cybercriminals poking around at it, so hopefully that holds up.
Who has to worry about this Microsoft Exchange hack?
These particular vulnerabilities were only present for those with on-premises Exchange. So, if your company has its own server and runs Outlook, this could very bad news for you. If you use Outlook but its through Exchange online or something comparable, you're probably okay. We don't know the full extent of the hack, but it's likely going to be much worse than the 30,000 company number currently reported, with ransomware or other cyber exploits coming in the very near future.
What can you do if you have Microsoft Exchange on your server?
Here are the tips from the Cybersecurity & Infrastructure Security Agency for both business leaders and IT staff: https://us-cert.cisa.gov/remediating-...
To summarize: Immediately update all instances of Microsoft Exchange on-premises if possible; create a forensic image of your system in the way they describe; check for indicators of compromise.
Overall, this is a tough one, because the exploits allow the cybecriminals to create their own rules and do almost anything they want within your email system. So, just be on the lookout, make sure you have everything backed up and is able to be recovered quickly, even though the weakness might still be saved within that backup, it'll at least help you from a complete business loss.
Do you have any questions or comments? Let me know down below!
*********************************************************
Subscribe for more videos like this- https://www.youtube.com/user/AlexMoen...
Check out more Biz Tech Tips:
Business IT tips ➤➤➤ • Biz Tech Tips
Are you looking for help with your IT for business? Email me and let me know: alex.moen at znws.com