Latest Alerts

Microsoft Outlook Vulnerability

Microsoft has released a recent advisory regarding a critical security vulnerability affecting Windows systems (Servers and Endpoints) using Microsoft Outlook CVE-2023-23397.

Laptop that is undergoing an error

Summary

Microsoft has issued a recent advisory regarding a critical security vulnerability affecting Windows systems (Servers and Endpoints) using Microsoft Outlook CVE-2023-23397.

This CRITICAL Vulnerability allows Cyber Criminals to steal credentials of Microsoft Outlook users with minimal complexity or effort. This vulnerability can be exploited by sending an email to a target user but does not require that user to open the email. It poses a dire threat to vulnerable organizations, as Cyber Criminals can repeatedly execute this attack and commandeer user accounts while the user is completely unaware.

 

Impact to Services

All customers with supported versions of Microsoft Outlook application for Windows are affected. Outlook for Mac, iOS or Android, or Outlook on the web are not affected.

 

Actions

To protect your organization, Microsoft and BOXX Hackbusters recommends that all organizations install the latest security patch for Microsoft Outlook immediately. To do this yourself you should do the following:

  • Open Outlook
  • Click on the File menu
  • Click on Office Account (some older versions may just say Account)
  • Click on Update Options
  • Select Update Now

If your organization usually manages updates, please verify with your IT Service Desk and ensure that they update all impacted systems.

Latest posts

Cyber Tips Cyber Insurance 101
Why Canadian Small Businesses Need to Buy Cyber Insurance

Why Canadian Small Businesses Need to Buy Cyber Insurance

Only 22% of Canadian small businesses carry standalone cyber insurance, even though most have already faced an attack. Here’s why getting modern cyber insurance matters and how it helps small businesses predict, prevent, respond to and recover from cyber threats.

Cyber Tips Cyber Insurance 101
Deepfake & AI Fraud: A Growing Cyber Risk for Canadian Businesses and Employees

Deepfake & AI Fraud: A Growing Cyber Risk for Canadian Businesses and Employees

Over 80% of Canadian businesses that experienced fraud in the past year also faced an AI-enabled attack. Here’s how deepfakes and AI-driven fraud are changing cyber risk and how modern cyber insurance and security tools protect your business and employees.

Cyber Tips Cyber Insurance 101
How Canadian Families Can Protect Young People and Children from Online Harms

How Canadian Families Can Protect Young People and Children from Online Harms

As Canada introduces Bill C-34, the Safe Social Media Act, families and caregivers still play an essential role in keeping children and their families safe online. Here’s how every household can build safer digital habits and strengthen cyber protection.

Sign up for the BOXX Insurance Newsletter

Get the latest updates about Cyber Insurance and Protection with our newsletter.