Microsoft Exchange emergency patch has raised eyebrows at the White House

representational image of a cloud firewall
(Image credit: Pixabay)

The White House says it is following the release of a new emergency patch from Microsoft with interest.

“We are closely tracking Microsoft’s emergency patch for previously unknown vulnerabilities in Exchange Server software and reports of potential compromises of U.S. think tanks and defense industrial base entities,” Jake Sullivan national security adviser to President Biden said on Twitter.

Concerns around cybersecurity among politicians have risen in recent months, particularly following the SolarWinds hack, which saw several branches of the US government targeted by still-unknown attackers, and the recent attack on Microsoft Exchange email servers.

Multiple threats

Earlier this week, it was revealed that security researchers had identified a “highly skilled and sophisticated” Chinese state-sponsored threat attack that used exploits in Microsoft Exchange.

The vulnerabilities have now been patched, with Microsoft urging all its business customers to update their Exchange server installations - a call echoed by Sullivan in his tweet.

The attackers, named Hafnium by the Microsoft Threat Intelligence Center (MSTIC) attacked targets in the United States. While it’s based in China, it uses leased Virtual Private Servers (VPS) in the US to run its malicious operations.

It is the second major cyberattack to target Microsoft systems in recent months, following the attack on SolarWinds in December 2020, where as well as multiple private companies being affected, nine federal agencies were also compromised.  

The SolarWinds hack has been called the “largest and most sophisticated attack the world has ever seen.” The breach involved SolarWinds Orion network monitoring software, which is used by an estimated 18,000 customers. Among these, it is believed that a smaller number of targets were subjected to follow-up intrusions.

Microsoft itself was targeted heavily by the SolarWinds attackers, who attempted to access and steal the source code behind some of the company's most popular products. However the company said it was able to block most of the attempts using its in-house Microsoft Defender software.

Via Reuters

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Read more
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
Image of someone clicking a cloud icon.
Microsoft's new expanded logging capabilities could mean big changes for US government devices
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring