Updating Exchange a Difficult Task
CF: Why do so many servers remain unpatched?
JH: Truthfully, updating Exchange can be hard. It takes a sizable amount of planning and coordination to take your email server out for maintenance. Even then, personnel need to be aware and fully understand the problem. Too often, we are seeing folks confusing this ProxyShell attack chain with the ProxyLogon vulnerability, and they might brush their shoulders thinking, ‘We patched in March, so we’re good.’ A significant amount of Huntress’ outreach has been the clarification and education on what this threat is, how to patch, and how to continue to hunt for webshells and indicators of compromise.