MYSECurity.TV

Home   /   RESOURCES   /   MYSEC.TV   / Microsoft Exchange hack and advice for threat hunting

Microsoft Exchange hack and advice for threat hunting

Tech & Sec Weekly
SHARE:

IN THIS VIDEO

Following Microsoft’s news about Hafnium, the Australian Cyber Security Centre (ACSC) advises organisations using Microsoft Exchange to urgently patch the following Common Vulnerabilities and Exposures (CVEs):

CVE-2021-26855 – server-side request forgery (SSRF) vulnerability in Exchange.
CVE-2021-26857 – insecure deserialization vulnerability in the Unified Messaging service.
CVE-2021-26858 – post-authentication arbitrary file write vulnerability in Exchange.
CVE-2021-27065 – post-authentication arbitrary file write vulnerability in Exchange.
If successfully exploited, these CVEs would allow an unauthenticated attacker to write files and execute code with elevated privileges on the underlying Microsoft Windows operating system.

A large number of Australian organisations are yet to patch vulnerable versions of Microsoft Exchange, leaving them vulnerable to compromise. The ACSC is encouraging these organisations to do so urgently.

We cross to the US and speak with Mat Gangwer, Senior Director, Sophos Managed Threat Response and review the Microsoft Exchange hack and threat hunting advice.

Full article, including updated ESET research: https://australiancybersecuritymagazi…

#Exchangehack#microsoft#cybersecurity#cyberbreach#exchange#CVE#Sophos

OTHER VIDEOS IN THIS SERIES

wi
May 28, 2026
Australian astronaut and 2026 Australian of the Year Katherine Bennell-Pegg joins Chris Cubbage on Australian Space TV in Perth to discuss how her dual role is shaping Australia’s space future. Fresh from outreach across Western Australia.Watch Now
st2
May 27, 2026
At MTX 2026, Mr Cheng Wee Kiang, Assistant Chief Executive (Engineering) at HTX (Home Team Science and Technology Agency), at the ST Engineering stand discusses how Singapore is advancing mission-critical public safety technologies.Watch Now
st1
May 27, 2026
At MTX 2026, we speak with Low Jin Phang, Chief Operating Officer for Public Safety & Security and President of Digital Systems at ST Engineering, about how AI, robotics, and space technology are reshaping public safety and security operations.Watch Now
gg
May 19, 2026
We speak with Qualys Managing Director for ANZ, Sam Salehi in the lead up to their Customer and Channel Partner event in Sydney on 28 May, 2026.Watch Now