Microsoft Exchange emergency patch has raised eyebrows at the White House

representational image of a cloud firewall
(Image credit: Pixabay)

The White House says it is following the release of a new emergency patch from Microsoft with interest.

“We are closely tracking Microsoft’s emergency patch for previously unknown vulnerabilities in Exchange Server software and reports of potential compromises of U.S. think tanks and defense industrial base entities,” Jake Sullivan national security adviser to President Biden said on Twitter.

Concerns around cybersecurity among politicians have risen in recent months, particularly following the SolarWinds hack, which saw several branches of the US government targeted by still-unknown attackers, and the recent attack on Microsoft Exchange email servers.

Multiple threats

Earlier this week, it was revealed that security researchers had identified a “highly skilled and sophisticated” Chinese state-sponsored threat attack that used exploits in Microsoft Exchange.

The vulnerabilities have now been patched, with Microsoft urging all its business customers to update their Exchange server installations - a call echoed by Sullivan in his tweet.

The attackers, named Hafnium by the Microsoft Threat Intelligence Center (MSTIC) attacked targets in the United States. While it’s based in China, it uses leased Virtual Private Servers (VPS) in the US to run its malicious operations.

It is the second major cyberattack to target Microsoft systems in recent months, following the attack on SolarWinds in December 2020, where as well as multiple private companies being affected, nine federal agencies were also compromised.  

The SolarWinds hack has been called the “largest and most sophisticated attack the world has ever seen.” The breach involved SolarWinds Orion network monitoring software, which is used by an estimated 18,000 customers. Among these, it is believed that a smaller number of targets were subjected to follow-up intrusions.

Microsoft itself was targeted heavily by the SolarWinds attackers, who attempted to access and steal the source code behind some of the company's most popular products. However the company said it was able to block most of the attempts using its in-house Microsoft Defender software.

Via Reuters

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Read more
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
Image of someone clicking a cloud icon.
Microsoft's new expanded logging capabilities could mean big changes for US government devices
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
Latest in Software & Services
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Autonomous finance
Quickbooks vs Quicken: what are the main strengths and weaknesses for your business
finance
Quickbooks vs Xero: which is the best for your business?
Group of people meeting
Zoom vs Google Meet: which is the best video conferencing tool for your business?
Fingers typing on a computer keyboard.
Microsoft 365 Personal vs Microsoft 365 Family: are there any real differences?
Latest in News
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before