Trusted by more than 2500 companies with over 5 million users
17 03, 2023

Microsoft March 2023 Patch Tuesday: Exchange Server Security Updates

2023-03-17T15:01:13-04:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security|

The March 2023 SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes. Although we are not aware of any active exploits in the wild, our recommendation is to install these updates immediately to protect your environment. Official announcement can be found here. Microsoft has released Security Updates (SUs) for [...]

17 03, 2023

Microsoft Exchange – Messageware Q1 2023 Newsletter

2023-03-17T11:48:36-04:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, News|

We’ve seen a wave of cyberattacks and data breaches that swept across the globe with multiple zero-day exploits discovered in Exchange Online and On-premises. Microsoft is urging admins to protect their Exchange Servers by keeping Exchange servers updated with the latest CUs and SUs. “Attackers looking to exploit unpatched Exchange servers are not going to go away.” [...]

14 03, 2023

Microsoft issues one month EOL warning for Exchange Server 2013

2023-03-14T07:18:00-04:00Blog, Exchange 2013|

Microsoft recently posted that users have a mere 31 days left to migrate away from Exchange Server 2013 before it reaches End-of-life (EOL). The Exchange Team has confirmed that even though support is ending soon, the software will still function past its expiration date. Taking this route is a bit of a risk as Microsoft won't be [...]

2 03, 2023

Microsoft Exchange Online Recovers from Worldwide Outage

2023-03-02T11:45:39-05:00Blog, Exchange 2016, Exchange 2019, Exchange Security, In The News|

Microsoft is looking into another global outage that has impacted Exchange Online, its cloud-based email system. The Microsoft 365 Status Twitter feed reported “impact is specific to users who are served through the affected infrastructure in North America, Europe, and the United Kingdom.” The thread continues,  "We're investigating an issue wherein users may be unable [...]

16 02, 2023

Microsoft February 2023 Patch Tuesday: Exchange Server Security Updates

2023-02-16T05:22:29-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security, Microsoft Exchange|

Microsoft has released patches to fix numerous vulnerabilities in the February 2023 Patch Tuesday release including remote code execution in Exchange Server. Official announcement can be found here. Microsoft has released Security Updates (SUs) for vulnerabilities found in: Exchange Server 2013 Exchange Server 2016 Exchange Server 2019 To learn more about these vulnerabilities, see the following [...]

2 02, 2023

Microsoft Urges Admins to Protect On-Premise Exchange Servers

2023-02-02T09:53:19-05:00Blog, Exchange 2016, Exchange 2019, Exchange Security|

“We’ve said it before, we’re saying it now, and we’ll keeping saying it: It is critical to keep your Exchange servers updated.” Microsoft is reminding admins once again not only to stay current on the latest Cumulative Update (CU) and Security Update (SU) on all Exchange servers, but to also perform manual tasks to harden [...]

17 01, 2023

Microsoft Exchange Server 2013 Nears End of Support

2023-01-17T04:12:49-05:00Blog, Exchange 2013, Exchange Security|

Exchange Server 2013 will reach its end of support on April 11, 2023. If you haven't already begun your migration from Exchange 2013 to Microsoft 365, Office 365, or Exchange 2019, now's the time to start planning. This means all security updates and patches will be ending soon!  After April 11th Microsoft will no longer [...]

13 01, 2023

Microsoft January 2023 Patch Tuesday: Exchange Server Security Updates

2023-01-13T10:27:53-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security|

Microsoft has released Security Updates (SUs) for vulnerabilities found in: Exchange Server 2013 Exchange Server 2016 Exchange Server 2019 The updates address the following vulnerabilities: CVE-2023-21745: Spoofing Vulnerability CVE-2023-21761: Information Disclosure Vulnerability CVE-2023-21762: Spoofing Vulnerability CVE-2023-21763: Elevation of Privilege Vulnerability CVE-2023-21764: Elevation of Privilege Vulnerability Official announcement can be found here. SUs are available for [...]

27 12, 2022

Ransomware Group Targets Microsoft Exchange Server with New Exploit OWASSRF

2022-12-27T07:28:49-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security, OWA Security|

Threat actors affiliated with the Play ransomware strain are leveraging a never-before-seen exploit method that bypasses Microsoft’s ProxyNotShell URL rewrite mitigation. A New Exploit Chain CrowdStrike researchers have discovered a new exploit method they have named OWASSRF, or Outlook Web Access Server-Side Request Forgery. The novel exploit affects Exchange Server 2013, 2016 and 2019 by leveraging CVE-2022-41080 [...]

19 12, 2022

Microsoft Exchange ProxyNotShell Vulnerability Explained and How to Mitigate It

2022-12-19T07:41:19-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security, Uncategorized|

ProxyShell and ProxyLogon are two high severity exploits against Microsoft Exchange Servers discovered in 2021. Both vulnerabilities enable threat actors to perform remote code execution on vulnerable systems. A year later, another easily exploitable vulnerability named ProxyNotShell is threatening unpatched Exchange Servers. Here's a great article we recommend you read: Microsoft Exchange ProxyNotShell vulnerability explained [...]

29 11, 2022

ProxyNotShell Proof-of-Concept Published Online

2022-12-16T10:05:26-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security|

Security researchers confirm Proof-of-Concept (PoC) works against unpatched versions of Microsoft Exchange Server 2013, 2016 and 2019 In early August, researchers discovered cyberattacks against critical infrastructure using two unpublished Exchange Server security vulnerabilities. Microsoft’s Security Research Center (MSRC) stated: “The first exploit identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows [...]

21 11, 2022

Microsoft Exchange – Messageware Q4 2022 Newsletter

2022-11-21T10:18:35-05:00News|

The last few months have been busy. Lets look at the happenings and news from the Exchange Server Community: MEC Technical Airlift We hope you attended the Microsoft Exchange Conference ( MEC Technical Airlift ) and had an opportunity to engage with the community and listen to the keynote with Rajesh, Perry, and Jared. In [...]

10 11, 2022

Microsoft November 2022 Patch Tuesday: Exchange Server Security Updates

2022-11-11T05:53:35-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security|

Microsoft has released security updates for two zero-day vulnerabilities: CVE-2022-41040, a server-side request forgery vulnerability, and CVE-2022-41082, which allows remote code execution. Collectively known as ProxyNotShell, the Exchange Server vulnerabilities have led to a spate of attacks linked to nation-state threat actors since late September. The SUs address vulnerabilities responsibly reported to Microsoft by security [...]

25 10, 2022

On-Premise Chosen over Microsoft 365 due to Server Privacy Concerns

2022-12-16T10:07:37-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, In The News|

In an ongoing battle that started in 2018 with the EU, several state courts, including the federal German court, found that Microsoft 365 was not compliant with GDPR laws. The ban mostly affects educational institutions and companies that use Microsoft’s 365 product line. The ban comes after Microsoft ended its special arrangements with German users. An [...]

12 10, 2022

Microsoft October 2022 Patch Tuesday: Exchange Server Security Updates

2022-12-16T10:11:03-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security|

The SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes. Our recommendation is to immediately install these updates to protect your environment. NOTE   The October 2022 SUs do not contain fixes for the zero-day vulnerabilities reported publicly on September 29, 2022 (CVE-2022-41040 and CVE-2022-41082). Please see this blog post to apply mitigations for those [...]

7 10, 2022

Alert: New Zero-Day Vulnerability Targets Microsoft On-Premise and Hybrid Cloud Exchange Servers

2022-12-16T10:12:07-05:00Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security|

Summary: In early August, researchers from the cybersecurity vendor GTSC discovered cyberattacks against critical infrastructure using two unpublished Exchange Server security vulnerabilities. Microsoft’s Security Research Center (MSRC) stated: “The first exploit identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows Remote Code Execution (RCE) when PowerShell [...]

26 09, 2022

Exchange Online Servers Hacked Using Malicious OAuth Applications

2022-12-16T10:13:14-05:00Blog, Exchange Security, Microsoft Exchange|

Microsoft’s 365 Defender Research Team recently investigated an attack in which malicious OAuth applications were deployed on compromised cloud tenants. Initial Access The attacker first needed to compromise a cloud user’s account that had sufficient permissions in order to create a malicious OAuth application. The threat actor did this by launching credential-stuffing attacks against high-risk [...]

19 09, 2022

CISA Publishes Mitigation Techniques Against Exchange Server Attacks

2022-12-27T07:19:46-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security|

In response to the recent targeting of critical infrastructure in the US and abroad, the Cybersecurity and Infrastructure Security Agency (CISA) urges network and security administrators to prepare and immediately mitigate potential cyber threats with the following measures. Implement and apply backup and recovery policies and procedures: Maintain offline backups of data Regularly test backup and restoration Ensure [...]

13 09, 2022

Nemesis Kitten targets Exchange Server for Attacks

2022-12-27T07:20:19-05:00Blog, Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security|

Microsoft Security Threat Intelligence has been tracking multiple ransomware campaigns by a group known as DEV-0270 who also goes by the alias Nemesis Kitten. Who is DEV-0270? DEV-0270, a sub-group of the Iranian threat actor known as PHOSPHORUS, are known for leveraging newly disclosed vulnerabilities against their targets. If successful, the group contacts the victim [...]

26 08, 2022

Microsoft Exchange Server Security: The 10 Best Ways to Secure Your Server

2022-09-16T04:09:53-04:00Exchange 2013, Exchange 2016, Exchange 2019, Exchange Security, OWA Security|

Security breaches cause organizational chaos, financial and reputation risk. Given how organizations have shifted to a hybrid of in-office and work-from-home, there is a significant increase in the security threat landscape, and it’s more important than ever to improve and harden Exchange Server security. These best practices help provide a baseline security framework that all [...]