CISA instructs U.S. government agencies to use Microsoft patches and anti-malware tools

U.S. government agencies are working to patch their technological weak spots.

When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.

What you need to know

What you need to know

U.S. government agencies with on-site variants of Microsoft Exchange Server havebeen instructedby the Cybersecurity and Infrastructure Security Agency (CISA) to use Microsoft patches and anti-malware tools to suss out any threats. All affected agencies are instructed to implement security hardening changes by June 28, 2021. The specific changes CISA is demanding can beread here.

This need for heightened security comes as a result of state-sponsoredChinese hackerstaking advantage of security flaws to steal Exchange Server data.Microsofthas a blog post detailing some specifics of the hacker organization, which has been dubbed Hafnium. According to the post, though Hafnium is based in China, the group’s members lease and use virtual private servers (VPS) in the U.S.

Microsoft hasanother postdetailing specifics of Hafnium’s activities, as well as the company’s efforts to stop them. That post goes into greater technical detail for anyone curious about the ins and outs of the cyber warfare currently being waged.

CISA is not happy about branches of the U.S. government being vulnerable to Hafnium. In CISA’s own words, “… this exploitation of Microsoft Exchange on-premises products poses an unacceptable risk to Federal Civilian Executive Branch agencies.” It’s no secret that the U.S. government has many enemies and way more threats than just a group of state-sponsored Chinese hackers to worry about, so the severity of potential vulnerabilities cannot be understated.

Microsoft claimsthat 92% of worldwide Exchange IPs have been patched or mitigated. Time will tell if the vulnerable percentages that remain end up being the only ones that matter.

Get the Windows Central Newsletter

Get the Windows Central Newsletter

All the latest news, reviews, and guides for Windows and Xbox diehards.

Robert Carnevale is the News Editor for Windows Central. He’s a big fan of Kinect (it lives on in his heart), Sonic the Hedgehog, and the legendary intersection of those two titans, Sonic Free Riders. He is the author ofCold War 2395. Have a useful tip? Send it to robert.carnevale@futurenet.com.