MYSEC.TV

Home   /   RESOURCES   /   MYSEC.TV   / Microsoft Exchange hack and advice for threat hunting

Microsoft Exchange hack and advice for threat hunting

Tech & Sec Weekly
SHARE:

IN THIS VIDEO

Following Microsoft’s news about Hafnium, the Australian Cyber Security Centre (ACSC) advises organisations using Microsoft Exchange to urgently patch the following Common Vulnerabilities and Exposures (CVEs):

CVE-2021-26855 – server-side request forgery (SSRF) vulnerability in Exchange.
CVE-2021-26857 – insecure deserialization vulnerability in the Unified Messaging service.
CVE-2021-26858 – post-authentication arbitrary file write vulnerability in Exchange.
CVE-2021-27065 – post-authentication arbitrary file write vulnerability in Exchange.
If successfully exploited, these CVEs would allow an unauthenticated attacker to write files and execute code with elevated privileges on the underlying Microsoft Windows operating system.

A large number of Australian organisations are yet to patch vulnerable versions of Microsoft Exchange, leaving them vulnerable to compromise. The ACSC is encouraging these organisations to do so urgently.

We cross to the US and speak with Mat Gangwer, Senior Director, Sophos Managed Threat Response and review the Microsoft Exchange hack and threat hunting advice.

Full article, including updated ESET research: https://australiancybersecuritymagazi…

#Exchangehack#microsoft#cybersecurity#cyberbreach#exchange#CVE#Sophos

OTHER VIDEOS IN THIS SERIES

sp12
November 17, 2025
We speak again with Jonathan Hung, Executive Director of the Office for Space Technology & Industry in Singapore, who outlines recent developments and future plans for OSTIn initiatives.Watch Now
mm32
November 13, 2025
Zoe Thompson, Head of Critical Infrastructure Protection at Thales Cyber Security, shares insights into how Thales is strengthening cybersecurity across Australia’s vital sectors — including energy, water, and telecommunications.Watch Now
mm23
November 13, 2025
Nick de Bont, Chief Security Officer at Thales, shares his perspective on safeguarding Australia and New Zealand’s critical infrastructure — from strategic defense sites to high-security manufacturing facilities.Watch Now
mm1
November 13, 2025
Mitchell Loughlin, Director of Risk and Resilience at Thales Cyber, explores the growing complexity of managing supply chain risks in today’s global environment.Watch Now