Patching an Absolute Must
Channel Futures: Is the problem unpatched servers? Is patching all that’s needed to protect these servers?
John Hammond: Patching the Exchange servers is an absolute must. It’s imperative that every organization update their Exchange servers to the July 2021 security releases at a minimum, but, they could have already been exploited prior to patching. The organization has to ensure there are no lingering webshells that could still grant threat actors access. Patching alone will not remove these webshells, and they must be removed manually. If any webshells are still accessible even after the patch has been applied, attackers still have system-level access to run any code, commands or programs they would like.