MYSECurity.TV

Home   /   RESOURCES   /   MYSEC.TV   / Microsoft Exchange hack and advice for threat hunting

Microsoft Exchange hack and advice for threat hunting

Tech & Sec Weekly
SHARE:

IN THIS VIDEO

Following Microsoft’s news about Hafnium, the Australian Cyber Security Centre (ACSC) advises organisations using Microsoft Exchange to urgently patch the following Common Vulnerabilities and Exposures (CVEs):

CVE-2021-26855 – server-side request forgery (SSRF) vulnerability in Exchange.
CVE-2021-26857 – insecure deserialization vulnerability in the Unified Messaging service.
CVE-2021-26858 – post-authentication arbitrary file write vulnerability in Exchange.
CVE-2021-27065 – post-authentication arbitrary file write vulnerability in Exchange.
If successfully exploited, these CVEs would allow an unauthenticated attacker to write files and execute code with elevated privileges on the underlying Microsoft Windows operating system.

A large number of Australian organisations are yet to patch vulnerable versions of Microsoft Exchange, leaving them vulnerable to compromise. The ACSC is encouraging these organisations to do so urgently.

We cross to the US and speak with Mat Gangwer, Senior Director, Sophos Managed Threat Response and review the Microsoft Exchange hack and threat hunting advice.

Full article, including updated ESET research: https://australiancybersecuritymagazi…

#Exchangehack#microsoft#cybersecurity#cyberbreach#exchange#CVE#Sophos

OTHER VIDEOS IN THIS SERIES

February 9, 2026
Dr. Peter Martin discusses the importance of Positioning, Navigation, and Timing (PNT) at PNT 2026, emphasising the need for adaptability in a denied environment.Watch Now
s1
February 9, 2026
Professor Suelynn Choy specialises in applications and methods of accurate and reliable positioning, and satellite remote sensing of the Earth atmosphere.Watch Now
spv1
February 6, 2026
Dr Alison Brown is the President and Chief Executive Officer of NAVSYS Corporation, which she founded in 1986. She is also CEO of PNTaaS.Watch Now
sp2
February 5, 2026
Professor Zak Kassas is a global leader in resilient and alternative PNT. He directs the U.S. Department of Transportation’s Center for Automated Vehicle Research with Multimodal AssurEd Navigation (CARMEN+) and leads the Autonomous Systems Perception, Intelligence & Navigation (ASPIN) Lab at The Ohio State University.Watch Now