Microsoft Defends Against New Threat to Exchange Mail Servers

Microsoft said it did not appear that hackers had taken advantage of the newly discovered weakness to break into Exchange email systems.

Advertisement
By Agence France-Presse | Updated: 14 April 2021 11:58 IST
Highlights
  • The vulnerabilities were different from those fixed last month
  • Microsoft in March released updates to fix the security flaws
  • The company said it has named the hacking groups "Hafnium"

The potentially devastating hack is believed to have affected at least 30,000 Microsoft email servers

Microsoft on Tuesday moved to defend against a dangerous new threat to Exchange email servers while the fight continued against hackers taking advantage of a flaw patched last month.

The US Cybersecurity and Infrastructure Security Agency, part of the Department of Homeland Security, called on government departments to immediately install the latest software update released by Microsoft.

"These vulnerabilities pose an unacceptable risk to the Federal enterprise and require an immediate and emergency action," CISA said in a notice.

Advertisement

"This determination is based on the likelihood of the vulnerabilities being weaponised, combined with the widespread use of the affected software across the Executive Branch and high potential for a compromise of integrity and confidentiality of agency information."

Advertisement

Both CISA and Microsoft said it did not appear that hackers had taken advantage of the newly discovered weakness to break into Exchange email systems.

"Although we are not aware of any active exploits in the wild, our recommendation is to install these updates immediately to protect your environment," Microsoft said in a post about the patch.

Advertisement

CISA and Microsoft said that the vulnerabilities were different from those fixed last month, when the US tech company disclosed that a state-sponsored hacking group operating out of China was exploiting security flaws in its Exchange email services to steal data from business users.

The company said the hacking group, which it has named "Hafnium," is a "highly skilled and sophisticated actor."

Advertisement

Hafnium has in the past targeted US-based companies including infectious disease researchers, law firms, universities, defense contractors, think tanks and NGOs.

The potentially devastating hack is believed to have affected at least 30,000 Microsoft email servers in government and private networks and has prompted calls for a firm response to state-sponsored attacks which could involve "hacking back" or other measures.

Microsoft in March released updates to fix the security flaws, which apply to on-premises versions of the software rather than cloud-based versions, and urged customers to apply them.

US Justice Department officials on Tuesday announced that, with backing from a court, they purged "malicious web shells" hackers had planted in hundreds of computers running Exchange Server software.

Web shells are bits of computer code that allow hackers to reach into computers remotely, and had been planted early this year by taking advantage of a weakness in Exchange, according to a Justice Department release.

"Today's operation removed one early hacking group's remaining web shells, which could have been used to maintain and escalate persistent, unauthorized access to US networks," Justice Department officials said.


Why did LG give up on its smartphone business? We discussed this on Orbital, the Gadgets 360 podcast. Later (starting at 22:00), we talk about the new co-op RPG shooter Outriders. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, and wherever you get your podcasts.

Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Microsoft
Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  2. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones Soon
  3. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  4. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  5. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  6. Xiaomi 17 Pro Max Tipped to Come With a Secondary Display
  7. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  8. Best Mobiles Under Rs. 60,000 in India
  9. OnePlus 15 Leaked Image Reveals Colourways, Redesigned Camera Module
  10. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  1. iOS 26 Update Released Alongside iPadOS 26 and macOS Tahoe: Check Eligible Models, How to Download
  2. Scientists Propose Space Missions to Chase Down Interstellar Comets
  3. Iceland Plume Discovery Reveals Ancient Volcanic Funnels Across North Atlantic
  4. Huawei Watch Ultimate 2 Design Renders Leaked, Could Launch Soon
  5. Marvel's Wolverine Will Reportedly Launch in 2026; Insomniac's Venom Game in 'Active Development'
  6. US President Donald Trump Challenges Block on Removing US Fed’s Lisa Cook
  7. iPhone 17 Series Outpaces iPhone 16 in Demand While iPhone 17 Pro Max Tops Pre-Orders, Analyst Says
  8. iPhone 16 Remained Top Selling Smartphone For Second Consecutive Quarter Globally: Report
  9. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
  10. iPhone 18 Series Tipped to Feature Smaller Dynamic Island, Might Launch Without Under-Display Face ID
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.