MYSEC.TV

Home   /   RESOURCES   /   MYSEC.TV   / Microsoft Exchange hack and advice for threat hunting

Microsoft Exchange hack and advice for threat hunting

Tech & Sec Weekly
SHARE:

IN THIS VIDEO

Following Microsoft’s news about Hafnium, the Australian Cyber Security Centre (ACSC) advises organisations using Microsoft Exchange to urgently patch the following Common Vulnerabilities and Exposures (CVEs):

CVE-2021-26855 – server-side request forgery (SSRF) vulnerability in Exchange.
CVE-2021-26857 – insecure deserialization vulnerability in the Unified Messaging service.
CVE-2021-26858 – post-authentication arbitrary file write vulnerability in Exchange.
CVE-2021-27065 – post-authentication arbitrary file write vulnerability in Exchange.
If successfully exploited, these CVEs would allow an unauthenticated attacker to write files and execute code with elevated privileges on the underlying Microsoft Windows operating system.

A large number of Australian organisations are yet to patch vulnerable versions of Microsoft Exchange, leaving them vulnerable to compromise. The ACSC is encouraging these organisations to do so urgently.

We cross to the US and speak with Mat Gangwer, Senior Director, Sophos Managed Threat Response and review the Microsoft Exchange hack and threat hunting advice.

Full article, including updated ESET research: https://australiancybersecuritymagazi…

#Exchangehack#microsoft#cybersecurity#cyberbreach#exchange#CVE#Sophos

OTHER VIDEOS IN THIS SERIES

spban
December 10, 2025
We speak with Professor Andrew Dempster, Director of the Australian Centre for Space Engineering Research discussing the PNT 2026 Conference – 4-6 February 2026 at Royal Randwick, Sydney.Watch Now
bann
December 10, 2025
We speak with Deepak Waghmare, CTO for APAC at Dell Technologies at Canalys APAC Forum 2025, held in Da Nang, Vietnam. Deepak, breaks down the rapidly evolving AI landscape, stressing that AI is still in its early stages and must deliver real business outcomes to gain lasting traction.Watch Now
banner-1
December 8, 2025
Luke Taylor, CEO of New Zealand–based managed security provider SSS, joins us on the sidelines of Canalys APAC Forum 2025, held in Da Nang, Vietnam to discuss the company’s sharp focus on identity, access, PKI and privileged access management.Watch Now
techsec-01
November 28, 2025
We cross to Orlando, Florida and speak with Yuriy Tsibere, Product Manager at ThreatLocker. We dive into the ThreatLocker DAC dashboard, built right into the ThreatLocker agent.Watch Now