URGENT – HAFNIUM: This bulletin is for anyone that has run Microsoft Exchange on premise within the last 6 months!

**URGENT SECURITY NOTIFICATION**

CVE-2021-26855 CVE-2021-26857 CVE-2021-26858 CVE-2021-27065 

Microsoft has announced that it has identified new nation-state cyberattacks, HAFNIUM, using previously unknown exploits that target the company’s on-premises Microsoft Exchange Server software. These vulnerabilities exist in on-premises Exchange Servers (that were utilized in the last six months) running versions 2010, 2013, 2016, and 2019. Microsoft 365 services (Office 365) do not appear to be impacted at this time. 

Microsoft released a patch to address the initial multiple remote code execution (RCE) vulnerabilities in Microsoft Exchange. To minimize or avoid impact, Microsoft highly recommends that immediate action is taken to apply this patch for any on-premise Exchange deployment.  While these patches may address the initial penetration we are working alongside our security partners to analyze ongoing and extended threats arising from this breach.   If you have migrated to Office 365 from Exchange within the last six months it is still possible that your network has been compromised and you need to take action.

If you are a Fusion IT managed services client this is already being addressed on your behalf! For our non-managed clients running an affected version of Exchange server, we highly recommend you apply the appropriate patch as soon as possible, or contact us if you would like one of our engineers to do this for you.

If you have any questions or concerns, please contact our support desk at 616-855-4590 or you can book a 10 minute discovery call with us to find out more.

Read more about this threat here: Microsoft HAFNIUM

For additional security bulletins go to https://fusion-it.net/security-bulletin/

Thank you!

Fusion IT, LLC

Interesting Image

Discovery Call Request

 

 

Important! We hate spam as much (or more!) than you and promise to NEVER rent, share, or abuse your e-mail address and contact information in any way.