Latest Alerts

Microsoft Exchange Security Vulnerability

Our Hackbusters team have issued this advisory bulletin from Microsoft regarding a critical vulnerability affecting Microsoft Exchange Servers.

Microsoft Exchange Security Vulnerability

The exploit named ‘Hafnium’ initially targeted entities in the United States for the purpose of exfiltrating information from a number of industry sectors but is now spreading globally. While Hafnium is based in China, it conducts its operations primarily from leased Virtual Private Servers (VPS) in the United States.

Scope

The vulnerability affects on-premises and hybrid Exchange Servers 2010, 2013, 2016, and 2019. The first priority are servers which are accessible from the Internet (e.g., servers publishing Outlook on the web/OWA and ECP). The vulnerability affects on-premises and hybrid Exchange Servers 2010, 2013, 2016, and 2019. The first priority are servers which are accessible from the Internet (e.g., servers publishing Outlook on the web/OWA and ECP). As of 9 March 2021, it has been estimated that 250,000 servers had already fallen victim to the attacks. This includes servers belonging to around 30,000 organizations in the United States, 7,000 servers in the United Kingdom, as well as the European Banking Authority and the Norwegian Parliament.

Note: If you are within a 100% cloud solution such as Office 365/Microsoft 365 environment, then this vulnerability may not affect you.

Actions

To protect your organization, Microsoft recommends organizations install the latest security patch as soon as possible.

Patch Links:

  1. March 2, 2021 Security Update Release – Release Notes – Security Update Guide – Microsoft

  2. CVE-2021-26412

  3. CVE-2021-26854

  4. CVE-2021-26855

  5. CVE-2021-26857

  6. CVE-2021-26858

  7. CVE-2021-27065

  8. CVE-2021-27078

We recommend that your security team assess whether or not the vulnerabilities were being exploited by using the Indicators of Compromise Microsoft shared here.

Cyberboxx policyholders affected by this vulnerability and need help from the Hackbusters team to address the mitigation actions, please contact your BOXX representative for assistance.

For additional information, please refer to the following resources:

As always, we will continue to be vigilant in monitoring for the latest cyber threats and vulnerabilities.

Latest posts

Cyber Tips Cyber Insurance 101
Deepfake & AI Fraud: A Growing Cyber Risk for Canadian Businesses and Employees

Deepfake & AI Fraud: A Growing Cyber Risk for Canadian Businesses and Employees

Over 80% of Canadian businesses that experienced fraud in the past year also faced an AI-enabled attack. Here’s how deepfakes and AI-driven fraud are changing cyber risk and how modern cyber insurance and security tools protect your business and employees.

Cyber Tips Cyber Insurance 101
How Canadian Families Can Protect Young People and Children from Online Harms

How Canadian Families Can Protect Young People and Children from Online Harms

As Canada introduces Bill C-34, the Safe Social Media Act, families and caregivers still play an essential role in keeping children and their families safe online. Here’s how every household can build safer digital habits and strengthen cyber protection.

Cyber Tips Cyber Insurance 101
Is Your Small Business as Prepared as Cyber Criminals for Quantum Computing?

Is Your Small Business as Prepared as Cyber Criminals for Quantum Computing?

AI is accelerating cyber attacks now. Cyber criminals are stealing your data for quantum computing later. Here’s what Canadian businesses need to know to prevent today’s cyber threats and prepare for tomorrow’s.

Sign up for the BOXX Insurance Newsletter

Get the latest updates about Cyber Insurance and Protection with our newsletter.