Trusted by more than 2500 companies with over 5 million users

Microsoft Exchange Server – Cumulative Updates – April 2022

On April 20, 2022 Microsoft released new Cumulative Updates: Exchange 2016 CU23 and Exchange 2019 CU12. The previous Cumulative Updates were released on September 28, 2021, more than 6 months ago.

Microsoft Exchange Server – Cumulative Updates – April 20222022-06-14T06:55:46-04:00

Microsoft March 2022 Patch Tuesday: 2 Exchange Server vulnerabilities fixed

The March 2022 SUs for Exchange Server address vulnerabilities responsibly reported by security partners and found through Microsoft’s internal processes. Although we are not aware of any active exploits in the wild, our recommendation is to install these updates immediately. These vulnerabilities affect on-premises Exchange Server, including servers used by customers in Exchange Hybrid mode. Exchange [...]

Microsoft March 2022 Patch Tuesday: 2 Exchange Server vulnerabilities fixed2022-06-01T12:18:47-04:00

Microsoft launches quarterly Cyber Security Intelligence Brief

Microsoft has just launched a quarterly cyber threat intelligence brief branded Cyber Signals. The new publication offers an expert perspective into the current threat landscape, discussing trending tactics, techniques, and strategies used by the world’s most prolific threat actors.  Cyber Signals is aimed at Chief Information Security Officers, Chief Information Officers, Chief Privacy Officers, and their teams, as they continue [...]

Microsoft launches quarterly Cyber Security Intelligence Brief2022-06-14T06:54:14-04:00

Microsoft revisits the Priority Account Protection in 365

Microsoft revisits the Priority Account Protection in 365:  (Microsoft 365 Defender): Applying a higher level of protection to accounts likely to be targeted by attackers is a more compelling offer as the last thing you want is for an executive to fall foul of a business email compromise attack or other phishing attempts like the recent Office VoIP voicemail [...]

Microsoft revisits the Priority Account Protection in 3652022-06-14T06:54:33-04:00

Microsoft Exchange Server – January 2022 Exchange Server Security Updates

January 2022 Exchange Server Security Updates Microsoft has released security updates for vulnerabilities found in: Exchange Server 2019 Cumulative Update 11 Security Update 3 (KB5008631) Exchange Server 2019 Cumulative Update 10 Security Update 4 (KB5008631) Exchange Server 2016 Cumulative Update 22 Security Update 3 (KB5008631) Exchange Server 2016 Cumulative Update 21 Security Update 4 (KB5008631) Exchange [...]

Microsoft Exchange Server – January 2022 Exchange Server Security Updates2022-06-14T06:56:33-04:00

Microsoft Exchange – Messageware Q4 2021 Newsletter

It's December, and there is plenty of good news... Microsoft has not released any December Exchange Server CUs or SUs, Messageware Exchange Server Guard now secures more Exchange Servers than ever, and the holiday season is upon us! But while everything feels a little more upbeat this week, the second half of 2021 was undoubtedly challenging, with [...]

Microsoft Exchange – Messageware Q4 2021 Newsletter2022-01-18T10:11:25-05:00

Microsoft Exchange Server Security – December 2021 CUs Postponed, Critical SUs Needed

Microsoft announces there is no major CU release for December 2021. Microsoft typically releases Cumulative Updates quarterly for Exchange Server 2019, 2016, and 2013. There have been a number of critical Security Updates since the latest September 2021 CUs: see KB5007409, KB5007012. For convenience, here are direct links to the Microsoft downloads for the latest [...]

Microsoft Exchange Server Security – December 2021 CUs Postponed, Critical SUs Needed2022-06-11T11:37:59-04:00

Microsoft Exchange Server Security – November 2021 Updates

The November 2021 security updates for Exchange Server address vulnerabilities reported by security partners and found through Microsoft’s internal processes. We are aware of limited targeted attacks in the wild using one of vulnerabilities (CVE-2021-42321), which is a post-authentication vulnerability in Exchange 2016 and 2019. Our recommendation is to install these updates immediately to protect your environment. For convenience, [...]

Microsoft Exchange Server Security – November 2021 Updates2022-06-11T11:37:33-04:00

Microsoft Exchange Server – October 2021 Exchange Server Security Updates

October 2021 Exchange Server Security Updates Microsoft has released security updates for vulnerabilities found in: Exchange Server 2013 CU23 (Exchange 2013 customers might also need to /prepareschema. Please see this post.) Exchange Server 2016 CU21 and CU22 Exchange Server 2019 CU10 and CU11 For full details refer to this article. Summary of updates:   Be sure to visit Messageware Security Products for Microsoft Exchange [...]

Microsoft Exchange Server – October 2021 Exchange Server Security Updates2022-06-11T11:48:59-04:00

Microsoft Exchange – Messageware Q3 2021 Newsletter

This year Hafnium exploited Microsft Exchange vulnerabilities. Other cyberattackers are following suit. But if you're like most organizations, you simply do not have the resources to protect against attackers constantly probing and attempting to access your Exchange Servers. Or do you? Let me explain. Messageware EPG can be your first line of defence against attackers. [...]

Microsoft Exchange – Messageware Q3 2021 Newsletter2022-06-11T11:35:53-04:00

Brute Force password attack causes massive disruption at hospital

Early in the morning, a sudden spike in calls to the helpdesk for password resets and releases swamped IT-support staff at a hospital network. User accounts were under attack and Active Directory lockouts were spreading fast. Together we installed Messageware Exchange Protocol Guard (EPG) to look in detail at Outlook Web and immediately two things [...]

Brute Force password attack causes massive disruption at hospital2023-09-19T10:29:34-04:00

Notes From the Field: Government agency stolen passwords bypass 2FA Security

The UK's National Cyber Security Centre (NCSC) is warning that criminals are looking to exploit the trend toward home office (Coronavirus) to conduct cyberattacks and hacking campaigns. These ‘phishing’ attempts have been seen in several countries and can lead to significant losses: financial, reputational, and sensitive data. And no one is immune —as you'll read [...]

Notes From the Field: Government agency stolen passwords bypass 2FA Security2023-04-24T06:53:38-04:00

Bots Automatically Target Credit Union’s Exchange Servers With Password Spray Attacks

Exchange Server Hacks: Notes From The Field Summary: In this article we look at how bots targeting a credit union's Exchange Servers with password spray attacks caused AD account lockouts. Cybersecurity is a top concern for everyone in the banking and financial sectors, and credit unions are no exception. The speed at which bots discover [...]

Bots Automatically Target Credit Union’s Exchange Servers With Password Spray Attacks2023-09-21T03:01:29-04:00

Microsoft Exchange – Messageware Q2 2021 Newsletter

The first half of 2021 has been a very challenging period for everyone with Microsoft Exchange Servers. Numerous zero-day attacks and hackers adjusting published code to work-around emergency patches stretched messaging team resources to the limit. Of interest during this period was the increased recognition that we want to know more about what is affecting [...]

Microsoft Exchange – Messageware Q2 2021 Newsletter2023-08-29T03:09:48-04:00

Exchange Protocol Guard – Software Release – EPG 3.6.1

Software Release - EPG 3.6.1 The following updates are now available now EPG 3.6.1  customers and trial users. Messageware EPG 2019 v3.6.1 Messageware EPG 2016 v3.6.1 Messageware EPG 2013 v3.6.1 Note: Prior to upgrading from 3.5 or earlier, make note of all entries in IP Filtering menu - Allow Lists tab. These IPs will need [...]

Exchange Protocol Guard – Software Release – EPG 3.6.12022-06-11T11:50:52-04:00

Timeline of Microsoft Exchange Server Zero-Day attacks

June 8, 2021 - Microsoft June 2021 Patch Tuesday: 50 vulnerabilities patched, six zero-days exploited in the wild Six out of seven zero-days are being actively used in cyberattacks. ... Microsoft June 2021 Patch Tuesday: 50 vulnerabilities patched, six zero-days ... Last month, Microsoft resolved 55 security flaws, four of which were deemed critical in ... flaws. .… [Read More] May 24, 2021 - [...]

Timeline of Microsoft Exchange Server Zero-Day attacks2022-11-10T12:12:37-05:00

Healthcare Provider Adds OWA SendTo / MailTo Functionality for Microsoft 365 with Citrix Profiles

  Microsoft 365 | Exchange Server: Notes From the Field In this edition of notes from the field, we share how a large Healthcare Provider was caught by surprise when they discovered that Microsoft 365 and Outlook Web broke their ability to email vital documents from their Human Resources intranet portal. In this case, the portal [...]

Healthcare Provider Adds OWA SendTo / MailTo Functionality for Microsoft 365 with Citrix Profiles2021-07-27T11:32:16-04:00

Telco Adds Exchange Server Protocol Guard to Prevent Account Lockouts Caused by 2FA Login Software

Exchange Server: Notes From the Field This case involves attacks at a division of a large Telco with a strong IT team operating more than sixty on-premises servers and mandated 2FA security solution for divisions managing their own Exchange Servers. And then … several incidents lead one Division’s security team to discover that password guessing [...]

Telco Adds Exchange Server Protocol Guard to Prevent Account Lockouts Caused by 2FA Login Software2023-09-07T10:31:07-04:00

Global Manufacturer Overcomes Microsoft 365 Limitations for Frontline Workers

Microsoft 365 | Exchange Server: Notes From the Field In this edition of notes from the field, we share how a Global Manufacturing company's messaging team was struggling to make Microsoft 365 a success. A single comment summarized the many challenges their Firstline workers were facing: "We've run into use cases where we are bumping [...]

Global Manufacturer Overcomes Microsoft 365 Limitations for Frontline Workers2022-06-11T10:13:56-04:00

Disgruntled ex-employee attacks Exchange Server with Outlook Mobile from their BYOD device

Exchange Server: Notes from the Field Support staff in a large manufacturing company were experiencing a sudden increase in the number of calls dealing with Active Directory user account lockouts and email password resets. The Exchange Server messaging group reached out to us for help. Together we installed Exchange Protocol Guard (EPG) to find out [...]

Disgruntled ex-employee attacks Exchange Server with Outlook Mobile from their BYOD device2023-04-24T06:54:36-04:00