Microsoft Releases Alternative Mitigations for Exchange Server Vulnerabilities | Eastern NC Now

The Cybersecurity and Infrastructure Security Agency (CISA) strongly urges its partners to follow guidance provided to Federal Civilian Executive Branch Departments and Agencies at cisa.gov/ed2102.

ENCNow
Press Release:

    The Cybersecurity and Infrastructure Security Agency (CISA) strongly urges its partners to follow guidance provided to Federal Civilian Executive Branch Departments and Agencies HERE. This CISA Emergency Directive outlines key steps federal officials must take to immediately address this vulnerability. We cannot stress enough the seriousness of this vulnerability; it is widespread and is indiscriminate.

    As a follow up to the conference call CISA held earlier today regarding the Microsoft Exchange widespread vulnerability affecting on-premise deployments, CISA published this evening the following Current Activity supplemental guidance to ensure all partners understand the severity of the vulnerability and steps to detect and mitigate potential compromise. All information surrounding this vulnerability can also be found directly HERE.

    NOTE: Exploitation of this vulnerability before patch installation permits an adversary to gain persistent access to and control of entire enterprise networks which is likely to persist even after patching.

    Please immediately speak with your IT officials to determine what steps your organization has taken, and if your organization does not have the technical capability to verify network integrity please consider bringing in a third party to assist you as soon as possible.

    Everyone using Microsoft Exchange on-premise products must:

  • Check for signs of compromise;
  • Immediately patch Microsoft Exchange with the vendor released patch;
  • If unable to patch, remove the products from the networkimmediately; and
  • Upgrade to the latest supported version of Microsoft Exchange.

    Response to indicators of compromise are essential to eradicate adversaries already on your network and must be accomplished in conjunction with measures to secure the Microsoft Exchange environment. Patching an already compromised system will not be sufficient to mitigate this situation; therefore, CISA strongly encourages partners to immediately disconnect any Microsoft Exchange systems suspected of being compromised.

    Please contact CISA for any questions or to report an incident regarding this vulnerability at Central@cisa.gov.

------- Actions for IT Admins/Staff -------

    CISA is tracking a serious issue with Microsoft Exchange. We cannot emphasis enough that exploitation is widespread and indiscriminate and we are advising all system owners to complete the following actions.

    Please follow the ensuing checklist and provide feedback to your leadership on the actions you have taken and any challenges completing the recommended steps.


    Respectfully,

    Cybersecurity and Infrastructure Security Agency
    Defend Today Secure Tomorrow
Go Back


Leave a Guest Comment

Your Name or Alias
Your Email Address ( your email address will not be published )
Enter Your Comment ( text only please )




Beaufort County Emergency Management: COVID-19 Update (3-8-20) News Services, Government, State and Federal Executive Order on Promoting Access To Voting


HbAD0

Latest State and Federal

Cheryl Hines. Dennis Quaid. Nicki Minaj. All became associated with the Trump administration. What happened next?
A federal grand jury in North Carolina has indicted former FBI Director James Comey on two charges related to making threats against President Donald Trump.
Their goal was simple: to put a Planned Parenthood in every mailbox in America.
Treasury officials allege these groups pose as humanitarian entities while covertly siphoning donations to Hamas.
President Donald Trump has publicly floated regime change and other aggressive actions toward Cuba.
With a new roadside plaque unveiled in Ellerbe on April 23, legendary wrestler and local resident André René Roussimoff is finally getting the formal recognition fans believe he deserves.
Following a string of attacks, critics are calling for denaturalizations. It's not that simple.
The solution is not to legalize the problem; it is to enforce the law consistently and deter future illegal immigration.
The teachers union is pushing to cancel school on May 1 as Chicago public schools continue to report dismal student proficiency rates.

HbAD1

Mission accomplished on sending inspiration from the dark side of the moon.
Two years ago, new media brought President Trump back to the White House. What happened?
Victims’ advocates, prosecutors, law enforcement officials, and families impacted by violent crime gathered Tuesday at the North Carolina State Archives building in Raleigh to recognize National Crime Victims’ Rights Week and honor those affected by crime across North Carolina.
The POLITICO poll found that almost half of respondents think Hollywood players should "be less vocal with their political beliefs."
"They help cultivate a radical hate America agenda, and we can't afford that same toxic ideology in America's War Department.”

HbAD2

 
 
Back to Top