In recent weeks, both Microsoft and cybersecurity companies have seen an increase in attacks on local Exchange servers. The target is a type of e-mail server most often used by small and medium-sized businesses, although larger organizations have also been affected.
Microsoft recalls that the vulnerabilities were exploited in the beginning in state attacks, but over time, they have attracted the attention of other cybercrime organizations. The latter used them to spread new attacks, including ransomware .
There is already talk of a large-scale attack, so protecting your systems is essential! Although Microsoft has regularly used methods to provide software updates, this extraordinary situation requires a more complex approach than applying updates. In addition to regular software updates, Microsoft also provides specific updates for older programs that are out of support, with the intent of providing quick protection.
The use of the SD-WAN system is, therefore, an upgrade from outdated computer network frameworks of the past as they are detached from traffic management and hardware-based monitoring functions.
The first step is to make sure that all relevant security updates are applied to each system . Find the version of Exchange Server you are using and apply the update! This will provide protection against known attacks and give your organization time to upgrade its servers to a version that has full security updates.
The next step is to identify the possibility that the systems have been compromised and, if so, remove them from the network . In this article you will find a recommended set of steps and tools to help you - including scripts that will allow you to look for clues to a possible compromise, a new version of Microsoft Safety Scanner to identify malware, and a new set of compromise indicators which is updated in real time.
Comments
Post a Comment