https://www.mpfinance.com/fin/in ... &issue=20210303
微軟(Microsoft)表示,發現再有中國支持的駭客利用多種先前未發現的漏洞侵入微軟客戶的電郵、聯繫人和日曆軟件系統,微軟公司敦促客戶下載相關軟件並進行修復。
微軟指,「與客戶和安全部門分享以上訊息是為了強調這些漏洞的關鍵特性,以及立即對受影響的系統加以修補」。微軟又指,受到影響的是微軟郵件本地版,線上版沒有受到影響。
微軟表示,相關駭客是「一群據分析身在中國並受到國家支持的人士」。他們通常瞄準的目標是「多種領域的美國實體,其中包括傳染病研究機構、高等教育機構、國防承包商、政策智庫以及非政府組織等。」
Microsoft’s release of patches for multiple different on-premises Microsoft Exchange Server zero-day vulnerabilities that are being exploited by a nation-state affiliated group.
The vulnerabilities exist in on-premises Exchange Servers 2010, 2013, 2016, and 2019. Exchange Online is not affected. We wanted to ensure you were aware of the situation and would ask that you help drive immediate remediation steps.
Microsoft highly recommends that you take immediate action to apply the patches for any on-premises Exchange deployments |