Home > Latest News > Thousands Of Aussie Businesses Caught Up In Microsoft Security Hack

Thousands Of Aussie Businesses Caught Up In Microsoft Security Hack

Thousands of Australian businesses and government agencies could have been affected by China-based attack on Microsoft’s Exchange server.

A major flaw in Microsoft’s software led to an aggressive hacking campaign which saw companies and government agencies around the world left vulnerable.

More than 7000 businesses using Microsoft Exchange servers in Australia were left exposed to the sophisticated cyberattack. It is unknown how many businesses may have been directly affected.

As Microsoft scrambled to patch any vulnerabilities, the hackers gained access to email servers and installed malicious software which can allow them to return to the target’s server at a later date.

The process – which affected Microsoft Exchange servers from 2013, 2016 and 2019 – is called ‘web shelling’.

According to the AFR, Australia ranked fourth in the world behind the United States, Germany and the UK as the most vulnerable countries to the attack.

Among the organisations used the affected email server was the ACT government. A spokesperson confirmed: “All patches were applied within 24 hours of being notified by Microsoft, and there is no evidence of compromise on ACT government systems”.

The Australian Cyber Security Centre (ACSC) yesterday advised companies using Microsoft Exchange to urgently patch any vulnerabilities.

“The ACSC is monitoring the situation and is able to provide assistance and advice as required,” an ACSC alert said.

“Microsoft has identified that if successfully exploited, these CVEs [common vulnerabilities and exposures] together would allow an unauthenticated attacker to write files and execute code with elevated privileges on the underlying Microsoft Windows operating system,” ACSC added today.

“Microsoft has observed instances where the attacker has uploaded web shells to maintain persistent access to compromise Exchange servers.”

Businesses affected by the hack are advised to follow Microsoft’s advice on web shelling to ensure the attackers can be locked out of the systems for good.

“A single web shell allowing attackers to remotely run commands on a server can have far-reaching consequences,” Microsoft wrote in a blog.



You may also like
Microsoft To Relaunch Controversial ‘Recall’ AI Feature
Canva Takes On Microsoft and Google With AI Product Overhaul as Revenue Hits A$4.9 Billion
Microsoft Fires Staff After AI Protest Over Israeli Military Contract at 50th Anniversary Celebration
Apple Shares At Nearly One-Year Low As Tech Stocks Plummet
Microsoft Expands AI Features to Intel and AMD-Powered Copilot Plus PCs

Popular Posts

Review: Google Pixel 9a Has Stunning Display At Serious Value
Latest News
/
/
Suunto Launches Lightweight Run Watch with Advanced Training Features
Latest News
/
/
Big European Appliance Brands Miele, Smeg Delonghi & Sennheiser Who Manufacture In China Dragged Into Tariff Fight
Latest News
/
/
Shein and Temu Hike Prices as Trump Tariffs Hit
Latest News
/
/
Apple Fixes Wireless CarPlay Bug with iOS 18.4.1 Update
Latest News
/
/

Digital Magazines

Recent Post

Review: Google Pixel 9a Has Stunning Display At Serious Value
Latest News
/
//
Comments are Off
If you’re hunting for a feature-packed phone without the premium price tag, the new Google Pixel 9a should be at...
Read More