MYSECurity.TV

Home   /   RESOURCES   /   MYSEC.TV   / Microsoft Exchange hack and advice for threat hunting

Microsoft Exchange hack and advice for threat hunting

Tech & Sec Weekly
SHARE:

IN THIS VIDEO

Following Microsoft’s news about Hafnium, the Australian Cyber Security Centre (ACSC) advises organisations using Microsoft Exchange to urgently patch the following Common Vulnerabilities and Exposures (CVEs):

CVE-2021-26855 – server-side request forgery (SSRF) vulnerability in Exchange.
CVE-2021-26857 – insecure deserialization vulnerability in the Unified Messaging service.
CVE-2021-26858 – post-authentication arbitrary file write vulnerability in Exchange.
CVE-2021-27065 – post-authentication arbitrary file write vulnerability in Exchange.
If successfully exploited, these CVEs would allow an unauthenticated attacker to write files and execute code with elevated privileges on the underlying Microsoft Windows operating system.

A large number of Australian organisations are yet to patch vulnerable versions of Microsoft Exchange, leaving them vulnerable to compromise. The ACSC is encouraging these organisations to do so urgently.

We cross to the US and speak with Mat Gangwer, Senior Director, Sophos Managed Threat Response and review the Microsoft Exchange hack and threat hunting advice.

Full article, including updated ESET research: https://australiancybersecuritymagazi…

#Exchangehack​ #microsoft​ #cybersecurity​ #cyberbreach​ #exchange​ #CVE​ #Sophos​

OTHER VIDEOS IN THIS SERIES

safty
September 30, 2026
Australia in Space TV host Chris Cubbage speaks with Maria Xygkaki, APAC Lead for Geospatial at Leonardo, about how InSAR (Interferometric Synthetic Aperture Radar) and the Cosmo-SkyMed satellite constellation are transforming the monitoring of critical infrastructure across Australia and the Indo-Pacific.Watch Now
mysec-clay
September 25, 2026
AIAA CEO Clay Mowry joins Chris Cubbage on Australia in Space TV to unpack Houston’s bid to host the International Astronautical Congress (IAC) in 2029.Watch Now
mysec-jacov
September 25, 2026
Chris Cubbage speaks with CyberPath technical program lead Jakub Zvěřina about Australia’s CyberPath Capability Framework and its role in the 2023–2030 Australian Cyber Security Strategy.Watch Now
cmmt
August 28, 2026
We’re joined by Ron Lear, Vice President of Global CMMI Strategies at the CMMI Institute and Pascal Rabbath, Certified High Maturity CMMI Lead Appraiser and Working Group member.Watch Now