DataBreachToday
Compliance
March 29, 2021
March 31, 2021
Compliance
DougOlenick) •
March 10, 2021
Get Permission
Microsoft's rerelease on Patch Tuesday of the seven patches for the widely exploited Exchange vulnerabilities has given security experts a chance to reiterate the urgent need to install these and other critical security updates.
"It’s imperative for organizations to ensure they’ve applied patches to address the Microsoft Exchange-related zero-days that were disclosed last week as part of an out-of-band advisory, which nation-state groups and other threat actors have exploited indiscriminately," says Satnam Narang, staff research engineer at Tenable.
On March 2, Microsoft issued emergency software patches for four zero-day vulnerabilities in Exchange email server; those were rereleased on Tuesday. The company says a China-based group it calls Hafnium has exploited the unpatched flaws in an attempt to gain persistent access to email systems (see: