MYSECurity.TV

Home   /   RESOURCES   /   MYSEC.TV   / Microsoft Exchange hack and advice for threat hunting

Microsoft Exchange hack and advice for threat hunting

Tech & Sec Weekly
SHARE:

IN THIS VIDEO

Following Microsoft’s news about Hafnium, the Australian Cyber Security Centre (ACSC) advises organisations using Microsoft Exchange to urgently patch the following Common Vulnerabilities and Exposures (CVEs):

CVE-2021-26855 – server-side request forgery (SSRF) vulnerability in Exchange.
CVE-2021-26857 – insecure deserialization vulnerability in the Unified Messaging service.
CVE-2021-26858 – post-authentication arbitrary file write vulnerability in Exchange.
CVE-2021-27065 – post-authentication arbitrary file write vulnerability in Exchange.
If successfully exploited, these CVEs would allow an unauthenticated attacker to write files and execute code with elevated privileges on the underlying Microsoft Windows operating system.

A large number of Australian organisations are yet to patch vulnerable versions of Microsoft Exchange, leaving them vulnerable to compromise. The ACSC is encouraging these organisations to do so urgently.

We cross to the US and speak with Mat Gangwer, Senior Director, Sophos Managed Threat Response and review the Microsoft Exchange hack and threat hunting advice.

Full article, including updated ESET research: https://australiancybersecuritymagazi…

#Exchangehack#microsoft#cybersecurity#cyberbreach#exchange#CVE#Sophos

OTHER VIDEOS IN THIS SERIES

set-4
January 23, 2026
Christopher Chai from Hackuity, a sponsor and exhibitor at the Ransomware Resilience 2026 conference in Kuala Lumpur, discussed his role in helping customers optimise their vulnerability management workflows to reduce attack surfaces.Watch Now
set-3
January 23, 2026
Peter Mosmans discussed chaos engineering and AI’s impact on ransomware resilience at the 2026 Ransomware Resilience Conference in Kuala Lumpur.Watch Now
set-2
January 23, 2026
Shahmeer Amir, a bug bounty hunter and CEO of SpeeQR, discussed the evolving threat of ransomware at the Ransomware Resilience 2026 conference in Kuala Lumpur.Watch Now
set-1
January 23, 2026
Indrani Chandrasegaran, Senior Director and Global Tech Services, Vcyberiz discussed her experiences at the Ransomware Resilience 2026 conference in Kuala Lumpur, emphasising the growing threat of ransomware and the importance of AI in cybersecurity defenses.Watch Now