
Microsoft Fixes Security Hole Used to Attack Outlook Users: Update Your Systems Now
Microsoft patched a vulnerability in Exchange Server that hackers were actively using to target people accessing their work email through a web browser.
Source
BleepingComputer
Original headline: Microsoft patches Exchange Server zero-day exploited in attacks
Plain-English summary by GetCyberRight. Read the full report at the source above.
Microsoft released an emergency security fix for its Exchange Server software after discovering that hackers were actively exploiting a vulnerability. The flaw allowed attackers to run malicious code when victims used Outlook Web Access, which is the browser-based version of Outlook email that many people use at work or for business accounts. This affects you if you use Outlook email through a web browser for work or business, particularly if your organization runs its own Exchange Server. The vulnerability could let hackers inject malicious code that runs when you view certain emails or click on links, potentially giving them access to your email contents, contacts, or even your login credentials.
If you use Outlook for work, take these steps immediately:
- Contact your IT department or the person who manages your email system and ask if they have applied the latest Microsoft security updates.
- Be extra cautious about clicking links in emails, even from people you know, until you confirm the patch is installed.
- Watch for any unusual activity in your email account, such as sent messages you did not write or new rules that forward your emails elsewhere.
- Change your email password as a precaution if your IT department confirms your system was vulnerable. For ongoing email security, remember that web-based email can be vulnerable to these types of attacks. Never click links in unexpected emails, even if they appear to come from colleagues or services you use. Always hover over links to see the actual destination before clicking. Keep your web browser updated, and log out of email when you finish using it rather than leaving the tab open indefinitely. These habits provide protection even when new vulnerabilities are discovered.
Curated from trusted cybersecurity sources by GetCyberRight
Source: BleepingComputerStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles
Nearly 11 Million Customer Records Lost by Japanese Power Company
A power company in Japan lost a storage drive with personal information of nearly 11 million people. Financial data was not included.
2 min readJapanese Power Company Lost Device With 11 Million Customer Records
A storage drive containing personal details of nearly 11 million customers went missing from a Japanese power company in May.
2 min readLouisiana Fire District Sues IT Company After Cyberattack
A fire district's network was compromised after their IT security provider allegedly failed to protect them properly. The district filed a lawsuit on March 20.
2 min readFire District Sues IT Company After Cyberattack Compromises Network
A Louisiana fire district is suing its IT security provider, claiming the company's failures allowed hackers to compromise the fire district's computer network.
2 min read