Microsoft Exchange Server has a zero day issue


VPN providers were forced to pull out of India this week as new data collection laws came into force across the country, and as the United Nations nations prepared to elect new heads of the International Telecommunications Union’s main internet standards body. There was a global ripple effect on technology policy.

Following the explosion and damage to the Nord Stream gas pipeline that runs between Russia and Germany, the destruction is being investigated as intentional and a complex search is underway to identify the perpetrators. The still-unidentified hackers are also hyperjacking victims and exfiltrating their data using a long-feared technique for hijacking virtualization software.

The infamous Lapsus$ hacker once again enjoys hacking, putting big corporations around the world at risk and issuing a dire but important warning that large institutions are indeed at risk. And Matrix, an end-to-end encrypted communication protocol, patched a serious and concerning vulnerability this week.

Pornhub has begun a trial of an automated tool that prompts users searching for child sexual abuse content to seek help with their actions. Cloudflare is also rolling out a free alternative to his Captcha in an attempt to validate humanity online without the headaches of finding a bike in a grid or deciphering blurry text. Did.

We provide advice on how to stand up against Big Tech and defend data privacy and user rights in your community, plus tips on the latest iOS, Chrome, and HP updates you should install.

And there are more. Each week we highlight news that we didn’t cover in detail on our own. Click the heading below to read the full article. Stay safe.

On Thursday night, Microsoft confirmed that two unpatched Exchange Server vulnerabilities were being actively exploited by cybercriminals. The vulnerability was discovered by a Vietnamese cybersecurity company named GTSC. According to GTSC postings on his website, two zero-days have been used in attacks against his customers since early August. According to the GTSC, the vulnerability only affects on-premises Exchange Servers to which attackers have authenticated access, but zero-days can chain and create backdoors to vulnerable servers. The vulnerability proved to be severe enough to allow an attacker to execute her RCE. [remote code execution] Of the compromised system, the researchers said.

In a blog post, Microsoft said the first flaw is a Server Side Request Forgery (SSRF) vulnerability and the second flaw allows remote code execution on a vulnerable server if the attacker has access to PowerShell. described as an attack. This post also provides guidance on how on-premises Microsoft Exchange customers can mitigate attacks.

Poor development operations and CIA negligence have allowed Iranian intelligence, in part, to identify and catch informants who risked their lives to provide information to the United States. follows the story of six Iranian men imprisoned as part of Iran’s aggressive counterintelligence campaign that began in 2009. Arrest and execution of dozens of CIA informants in Iran and China. In 2018, Yahoo News reported on the system.

The CIA appeared to have bought web hosting space en masse from the same provider, so Reuters launched hundreds of secret secrets aimed at facilitating communications between informants and their CIA personnel around the world. I was able to enumerate the CIA website. The sites, which are no longer active, were devoted to topics such as beauty, fitness and entertainment. Among them was a Star Wars fan page, according to Reuters. Two former CIA officers said each fake her website was assigned to only one of her spies in order to limit network-wide exposure in case one agent was caught. He told the media that he was.

Former CIA counterintelligence chief James Olson told Reuters:

A former National Security Agency official was charged Wednesday with three counts of violating the Espionage Act for allegedly trying to sell classified national defense information to an unnamed foreign government, according to court documents released this week. was done. In a press release about the arrest, the U.S. Department of Justice said that Jareh Sebastian Dalke, of Colorado Springs, Colorado, used an encrypted email to send excerpts of three classified documents to an undercover FBI agent. said. foreign government. Darke told his agent that he was in serious financial debt and needed compensation in cryptocurrency in exchange for the information.

The FBI arrested Dalk on Wednesday as he arrived at Union Station in downtown Denver and delivered classified documents to an undercover agent. If convicted, he could face life in prison or the death penalty.

On Tuesday, hackers hijacked Fast Company’s content management system to send two obscene push notifications to followers of the publication Apple News. In response, the publication’s parent company, Mansueto Ventures, closed his and his, which he also owned. Fast Company issued a statement calling the message despicable and not in keeping with the content and spirit of the outlet.In an article the hacker supposedly posted on his Fast Company website, many, including the administrator, claiming to have accessed it via a password shared with their account.

As of yesterday, the company’s website was still offline, instead redirecting to a statement about the hack.




