MYSECurity.TV

Home   /   RESOURCES   /   MYSEC.TV   / Microsoft Exchange hack and advice for threat hunting

Microsoft Exchange hack and advice for threat hunting

Tech & Sec Weekly
SHARE:

IN THIS VIDEO

Following Microsoft’s news about Hafnium, the Australian Cyber Security Centre (ACSC) advises organisations using Microsoft Exchange to urgently patch the following Common Vulnerabilities and Exposures (CVEs):

CVE-2021-26855 – server-side request forgery (SSRF) vulnerability in Exchange.
CVE-2021-26857 – insecure deserialization vulnerability in the Unified Messaging service.
CVE-2021-26858 – post-authentication arbitrary file write vulnerability in Exchange.
CVE-2021-27065 – post-authentication arbitrary file write vulnerability in Exchange.
If successfully exploited, these CVEs would allow an unauthenticated attacker to write files and execute code with elevated privileges on the underlying Microsoft Windows operating system.

A large number of Australian organisations are yet to patch vulnerable versions of Microsoft Exchange, leaving them vulnerable to compromise. The ACSC is encouraging these organisations to do so urgently.

We cross to the US and speak with Mat Gangwer, Senior Director, Sophos Managed Threat Response and review the Microsoft Exchange hack and threat hunting advice.

Full article, including updated ESET research: https://australiancybersecuritymagazi…

#Exchangehack#microsoft#cybersecurity#cyberbreach#exchange#CVE#Sophos

OTHER VIDEOS IN THIS SERIES

sp2
May 7, 2026
Frederico Spengler, Business Development Manager from Deloitte’s Center for the Edge in Southeast Asia discusses Deloitte’s efforts to build its space practice in the region, drawing on the firm’s global experience and network of more than 600 practitioners.Watch Now
txt1
May 7, 2026
Nicolette Yeo, General Manager of Singapore Space & Technology (SST) Think Tank, shares what to expect from Global Space Technology Convention & Exhibition (GSTCE) 2026 in Singapore and why the commercialisation of space matters now.Watch Now
acsm1
May 1, 2026
We speak with Lakshmi Hanspal, Chief Trust Officer, DigiCert in Sydney.Watch Now
secrisk
April 29, 2026
The Security Risk: Middle East and Ukraine Conflict – Impact on Australia’s National Security brings together leading experts to unpack how global instability is reshaping the security landscape closer to home.Watch Now