Microsoft Exchange has been hacked.
(archive.is)
You're viewing a single comment thread. View all comments, or full comment thread.
Comments (2)
sorted by:
I've been dealing with this. There are 4 different exploits that when combined can give Chinese hackers access to your system. A lot of it would be manual work but the problem is that once the server is exploited it could allow access for some time to come and that could lead to full network access.
There's a script you can use to check your server here: https://github.com/microsoft/CSS-Exchange/tree/main/Security
If you can't update to the latest CU and patch then your best option is to disable access to 80/443 from outside of your network till you can. Your only hurdle is management stopping you because "they need email on there phones".