Security News

NSA Discovers New Vulnerabilities Affecting Microsoft Exchange Servers
2021-04-14 22:57

In its April slate of patches, Microsoft rolled out fixes for a total of 114 security flaws, including an actively exploited zero-day and four remote code execution bugs in Exchange Server. Cybersecurity firm Kaspersky, which discovered and reported the flaw to Microsoft in February, linked the zero-day exploit to a threat actor named Bitter APT, which was found exploiting a similar flaw in attacks late last year.

Microsoft moves Windows 10 21H1 to the Release preview channel
2021-04-14 19:47

Microsoft is now installing the Windows 10 21H1 build in the Release preview channel, indicating that it will likely be released later this month or in May. Windows 10 21H1 is the next feature update to be released and delivered as an enablement package that enables dormant features already installed on Windows 10 2004 and Windows 20 20H2. Microsoft began testing the Windows 10 21H1 feature update in February after releasing it on the Windows Insider 'Beta' channel. Yesterday, Microsoft announced that they had moved the Windows 10 21H1 feature update to the 'Release' channel, which indicates that they are very close to releasing it.

Microsoft Has Busy April Patch Tuesday with Zero-Days, Exchange Fixes
2021-04-14 12:46

Microsoft had its hands full Tuesday snuffing out five zero-day vulnerabilities, a flaw under active attack and applying more patches to its problem-plagued Microsoft Exchange Server software. Of note, the U.S. National Security Agency released information on four critical Exchange Server vulnerabilities impacting versions released between 2013 and 2019.

Spy agency GCHQ told me Gmail's more secure than Microsoft 365, insists British MP as facepalming security bods tell him to zip it
2021-04-14 09:16

Conservative MP Tom Tugendhat has publicly claimed GCHQ sources told him Gmail was more secure than Parliament's own Microsoft Office 365 deployment - but both Parliament and a GCHQ offshoot have told him to stop being silly. "I was told by friends at GCHQ that I was better off sticking to Gmail rather than using the parliamentary system because it was more secure," Tugendhat told the BBC's Today Programme.

FBI removes web shells from hacked Microsoft Exchange servers
2021-04-14 07:56

Authorities have executed a court-authorized operation to copy and remove malicious web shells from hundreds of vulnerable on-premises versions of Microsoft Exchange Server software in the United States. Through January and February 2021, certain hacking groups exploited zero-day vulnerabilities in Microsoft Exchange Server software to access email accounts and place web shells for continued access.

FBI Agents Secretly Deleted Web Shells From Hacked Microsoft Exchange Servers
2021-04-14 04:03

FBI agents executed a court-authorized cyber operation to delete malicious web shells from hundreds of previously hacked Microsoft Exchange servers in the United States, unbeknownst to their owners, the U.S. Department of Justice said Tuesday. After a wave of major in-the-wild zero-day attacks against Exchange Server installations that occurred globally in January, savvy organizations scrambled to lock down vulnerable Microsoft email servers and remove web shells that were installed by attackers.

FBI deletes web shells from hundreds of compromised Microsoft Exchange servers before alerting admins
2021-04-14 02:26

The FBI deleted web shells installed by criminals on hundreds of Microsoft Exchange servers across the United States, it was revealed on Tuesday. "Although many infected system owners successfully removed the web shells from thousands of computers, others appeared unable to do so, and hundreds of such web shells persisted unmitigated," the Justice Department noted in an announcement.

Microsoft Patch Tuesday, April 2021 Edition
2021-04-13 23:12

Microsoft today released updates to plug at least 110 security holes in its Windows operating systems and other products. The patches include four security fixes for Microsoft Exchange Server - the same systems that have been besieged by attacks on four separate bugs in the email software over the past month.

NSA helps out Microsoft with critical Exchange Server vulnerability disclosures in an April shower of patches
2021-04-13 19:47

April showers bring hours of patches as Microsoft delivers its Patch Tuesday fun-fest consisting of over a hundred CVEs, including four Exchange Server vulnerabilities reported to the company by the US National Security Agency. "This month's release includes a number of critical vulnerabilities that we recommend you prioritize, including updates to protect against new vulnerabilities in on-premise Exchange Servers," Microsoft said in its blog post.

Microsoft April 2021 Patch Tuesday fixes 108 flaws, 5 zero-days
2021-04-13 17:39

Today is Microsoft's April 2021 Patch Tuesday, and with it comes five zero-day vulnerabilities and more Critical Microsoft Exchange vulnerabilities. With today's update, Microsoft has fixed 108 vulnerabilities, with 19 classified as Critical and 89 as Important.