Hackers are racing to take advantage of unpatched Microsoft Exchange servers

Microsoft logo at Ignite
Microsoft logo at Ignite (Image credit: Windows Central)

What you need to know

  • A strain of ransomware called DearCry is being used to target unpatched Exchange servers.
  • Microsoft has released patches for Exchange servers, but some organizations have not patched systems yet.
  • Check Point Research reports that exploitation attempts doubled every 2-3 hours over a recent 24-hour period.

Microsoft has detected and is now blocking the new family of ransomware, but it's still vital for organizations to patch their servers and take other security measures.

The Microsoft Security Intelligence Twitter account discussed the ransomware recently. A subsequent Tweet explains that Microsoft Defender customers utilizing automatic updates don't need to take any additional action.

According to Check Point Research (CPR), threat actors are increasing their attacks on vulnerable servers. Over 24 hours, CPR saw exploitation attempts on organizations double every 2-3 hours.

CPR states in its blog:

Since the recently disclosed vulnerabilities on Microsoft Exchange Servers, a full race has started amongst hackers and security professionals. Global experts are using massive preventative efforts to combat hackers who are working day-in and day-out to produce an exploit that can successfully leverage the remote code execution vulnerabilities in Microsoft Exchange.

CPR explains that if an attacker manages to utilize unpatched vulnerabilities, they can obtain corporate emails and place damaging code within organizations.

Sean Endicott
News Writer and apps editor

Sean Endicott is a news writer and apps editor for Windows Central with 11+ years of experience. A Nottingham Trent journalism graduate, Sean has covered the industry’s arc from the Lumia era to the launch of Windows 11 and generative AI. Having started at Thrifter, he uses his expertise in price tracking to help readers find genuine hardware value.

Beyond tech news, Sean is a UK sports media pioneer. In 2017, he became one of the first to stream via smartphone and is an expert in AP Capture systems. A tech-forward coach, he was named 2024 BAFA Youth Coach of the Year. He is focused on using technology—from AI to Clipchamp—to gain a practical edge.