{"id":14520,"date":"2021-03-16T21:05:48","date_gmt":"2021-03-16T20:05:48","guid":{"rendered":"https:\/\/www.secuinfra.com\/?p=14520"},"modified":"2021-03-16T21:05:48","modified_gmt":"2021-03-16T20:05:48","slug":"tenfold-increase-in-incident-response-operations-at-secuinfra-due-to-exchange-vulnerability","status":"publish","type":"post","link":"https:\/\/www.secuinfra.com\/en\/news\/tenfold-increase-in-incident-response-operations-at-secuinfra-due-to-exchange-vulnerability\/","title":{"rendered":"Tenfold increase in incident response operations at SECUINFRA due to Exchange vulnerability"},"content":{"rendered":"<p>According to the Federal Office for Information Security (BSI), by the time Microsoft officially announced the Exchange vulnerability on March 3, 2021, it was already being exploited by APT groups like Hafnium, LuckyMouse, and Calypso\u00a0(BSI, 2021).<\/p>\n<p>The announcement of the vulnerability can, with little exaggeration, be compared to the triggering of an avalanche. Since then, APT groups around the world have been working 24\/7 to write exploits, incorporate the vulnerability into their tools, and attack every vulnerable Exchange server. It\u2019s not just about stealing emails and contact information. For some time, hackers have been attempting to penetrate companies, capture domain controllers (AD), steal additional data, and plant malicious code and back doors in company infrastructure as long-term entrenchment.<\/p>\n<p>This is only the third time since the BSI was founded that it has declared the highest security warning level. It\u2019s more than justified. According to the President of the BSI, Arne Sch\u00f6nbohm, since the security gap was found, \u201croughly 65,000 vulnerable servers belonging to businesses, authorities, and other institutions in Germany have been identified. Hackers who manage to take over Exchange can also easily penetrate into other internal IT systems. The threat represented by the current vulnerability goes far beyond Exchange.\u201d (Kuhn, 2021)<\/p>\n<p>Since the vulnerability was discovered, SECUINFRA has registered a tenfold increase in digital forensics and incident response (DFIR) operations. Based on our operations, we can confirm the BSI President\u2019s appraisal. It\u2019s no longer only about Exchange. Anyone who is affected and doesn\u2019t act now is being grossly negligent and risking their company\u2019s integrity.<\/p>\n<p>According to the BSI President, after security updates are installed, \u201cthe entire IT systems needs to be checked and cleared of any form of hacker activity\u201d (Kuhn, 2021).<\/p>\n<p>SECUINFRA is ready for this with its\u00a0<a href=\"https:\/\/www.secuinfra.com\/en\/services\/compromise-assessment\/\">Compromise Assessment<\/a> service. These are routine operations for our cyber defense experts. For our customers, the key issue is answering the urgent question: \u201cHave other systems aside from the Exchange server been compromised?\u201d SECUINFRA\u2019s cyber defense experts can answer this question quickly and precisely.<\/p>\n<p><a href=\"https:\/\/www.secuinfra.com\/en\/contact\/\">CONTACT US<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>BSI, 2021\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Federal Office for Information Security (March 14, 2021), Microsoft Exchange Vulnerabilities,<\/p>\n<p><a  href=\"https:\/\/www.bsi.bund.de\/SharedDocs\/Downloads\/DE\/BSI\/Cyber-Sicherheit\/Vorfaelle\/Exchange-Schwachstellen-2021\/MSExchange_Schwachstelle_Detektion_Reaktion.pdf?__blob=publicationFile&amp;v=3\"  dpc-external=\"true\"  target=\"_blank\"  rel=\"nofollow\" >https:\/\/www.bsi.bund.de\/SharedDocs\/Downloads\/DE\/BSI\/Cyber-Sicherheit\/Vorfaelle\/Exchange-Schwachstellen-2021\/MSExchange_Schwachstelle_Detektion_Reaktion.pdf?__blob=publicationFile&amp;v=3<\/a><\/p>\n<p>Kuhn, 2021\u00a0\u00a0\u00a0\u00a0 Kuhn, T. (March 14, 2021), Die Bedrohung reicht weit \u00fcber Microsoft Exchange hinaus (\u201cThe threat goes far beyond Microsoft Exchange\u201d), WirtschaftsWoche,<\/p>\n<p><a  href=\"https:\/\/www.wiwo.de\/technologie\/digitale-welt\/cybersicherheit-die-bedrohung-reicht-weit-ueber-microsoft-exchange-hinaus\/26996784.html\"  dpc-external=\"true\"  target=\"_blank\"  rel=\"nofollow\" >https:\/\/www.wiwo.de\/technologie\/digitale-welt\/cybersicherheit-die-bedrohung-reicht-weit-ueber-microsoft-exchange-hinaus\/26996784.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>According to the Federal Office for Information Security (BSI), by the time Microsoft officially announced the Exchange vulnerability on March 3, 2021, it was already being exploited by APT groups [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":14516,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[60],"tags":[],"dpc_coauthors":[],"class_list":["post-14520","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/posts\/14520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/comments?post=14520"}],"version-history":[{"count":0,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/posts\/14520\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/media\/14516"}],"wp:attachment":[{"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/media?parent=14520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/categories?post=14520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/tags?post=14520"},{"taxonomy":"dpc_coauthors","embeddable":true,"href":"https:\/\/www.secuinfra.com\/en\/wp-json\/wp\/v2\/dpc_coauthors?post=14520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}