Is this a working weekend for you, the on-premises Exchange Server Support teams?
The Microsoft Threat Intelligence Center (MSFIC) has detected multiple cyberattacks to on-premises Microsoft Exchange Servers.
The threat actor known as Hafnium originates from China but operates within the US.
The affected versions are Exchange Server 2013. Exchange Server 2016, and Exchange Server 2019.
These are the steps we suggest performing immediately:
- Check your servers for these security updates.
- Bring the backup of your servers and mailboxes up-to-date.
- Disconnect your servers from the Internet.
- Patch your servers.
- Verify your servers for full operational.
- Scan your server logs for compromise.
Don’t wait, set your goal to shield yourself against malicious actors. Now is the time to move your exchange mail services to the cloud.
We can do it for you. Contact Us.
Susie Chow – ITensure
Call/Text: (714) 633-9454