Jump to content

CISA gives federal agencies 5 days to find hacked Exchange servers - Piracy News and Crypto Updates - InviteHawk - Your Only Source for Free Torrent Invites

Buy, Sell, Trade or Find Free Torrent Invites for Private Torrent Trackers Such As redacted, blutopia, losslessclub, femdomcult, filelist, Chdbits, Uhdbits, empornium, iptorrents, hdbits, gazellegames, animebytes, privatehd, myspleen, torrentleech, morethantv, bibliotik, alpharatio, blady, passthepopcorn, brokenstones, pornbay, cgpeers, cinemageddon, broadcasthenet, learnbits, torrentseeds, beyondhd, cinemaz, u2.dmhy, Karagarga, PTerclub, Nyaa.si, Polishtracker etc.

CISA gives federal agencies 5 days to find hacked Exchange servers


Recommended Posts

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to scan their networks again for any signs of compromised on-premises Microsoft Exchange servers and report their findings within five days.

CISA issued another directive ordering federal agencies to urgently update or disconnect their Exchange on-premises servers after Microsoft released security updates for zero-day bugs collectively dubbed ProxyLogon.

Earlier this month, CISA officials said that, so far, no US federal civilian agencies were compromised in ongoing attacks targeting vulnerable Exchange servers.

The newly issued emergency directive provides federal civilian executive branch agencies with additional forensic triage and server hardening requirements.

"Specifically, this update directs federal departments and agencies to run newly developed tools —Microsoft’s Test-ProxyLogon.ps1 script and Safety Scanner MSERT—to investigate whether their Microsoft Exchange Servers have been compromised," the CISA said.

Microsoft Exchange supplemental guidance

The federal agencies are required to use tools developed by Microsoft to help organizations investigate if their Exchange servers have been compromised in ProxyLogon attacks:

By 12:00 PM EDT on Monday, April 5, 2021, download and run the current version of Microsoft Safety Scanner (MSERT) in Full Scan mode and report results to CISA using the provided reporting template.

By 12:00 PM EDT on Monday, April 5, 2021, download and run the Test-ProxyLogon.ps1 script as an administrator to analyze Exchange and IIS logs and discover potential attacker activity. Report results to CISA using the provided reporting template.

CISA also asked agencies that find any evidence of compromise using Microsoft's new tools to immediately report it "as an incident."

The emergency directive also requires that all agencies further harden their on-premises Exchange servers by 12:00 PM EDT on Monday, June 28, 2021.

Required hardening measures include provisioning firewalls, installing updates within 48 hours after they're released, using only supported software versions, configuring logging and storing logs off-site for at least 6 months, and installing anti-malware on all on-premises servers.

"Although the Emergency Directive only applies to Federal Civilian Executive Branch agencies, CISA encourages state and local governments, critical infrastructure entities, and other private sector organizations to review the supplemental direction [..] for additional information," CISA added.

Ongoing attacks targeting Exchange servers

Microsoft disclosed ongoing attacks coordinated by several Chinese-backed hacking groups targeting the vulnerabilities.

Slovak internet security firm ESET also shared info on at least ten more hacking groups actively abusing these bugs.

Attackers target orgs from multiple industry sectors worldwide, stealing sensitive information, deploying cryptomining malware or ransomware [1, 2] on on-premises Exchange servers.

From over 400,000 vulnerable servers impacted by the ProxyLogon flaws on March 2 when Microsoft disclosed the bugs, there are now under 30,000 still exposed to attacks after 92% of them were patched within a month.

Link to comment
Share on other sites

Avoid unnecessary posts such as 'Thank you', 'Welcome', etc. Such posts will be deleted and user will be warned if it happens again. If caught spamming, the following actions are applicable -

  • First time - Warning
  • Second time - 5000 Points will be deducted
  • Third time - Ban for 7 days
  • Fourth time - Permanent Ban

If the post helped you, reward the user by reacting to the post like this -

1.jpg

Link to comment
Share on other sites

The last post in this topic was made more than 14 days ago. Only post in this topic if you have something valuable to add. Irrelevant posts are not allowed and you will be warned/banned for spamming old topics.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Read this before posting -
  • Only post if you have something valuable to contribute.
  • Avoid unnecessary posts such as 'Thank you', 'Welcome', etc. Such posts will be deleted and you will be warned if it happens again.
  • If the post helped you, reward the user by reacting to the post like this -                      1.jpg
Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Customer Reviews

  • Similar Topics

×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.