The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the NSA and international partners from Australia and Canada, released comprehensive best practices to secure on-premises Microsoft Exchange Servers. This guidance addresses the persistent threat posed by attackers exploiting vulnerabilities in Exchange, especially as some versions reach end-of-life and no longer receive security updates. Key recommendations include restricting administrative access, enforcing multi-factor authentication (MFA), and implementing strong transport security measures such as TLS and HSTS to protect communications and reduce the attack surface.
Industry experts emphasize that organizations should treat this guidance as a critical call to action, urging security teams to refine threat models, conduct tabletop exercises, and foster collaboration between IT, DevOps, and business leaders. The guidance highlights the importance of consistent patching, least privilege, and segmentation as foundational defenses against ongoing threats targeting Exchange environments. Organizations are encouraged to use this opportunity to reassess their security investments and ensure robust protection for their communication infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A Cyberthrone article published guidance summarizing CISA best practices for securing Microsoft Exchange. Based on the provided reference, this is a defensive guidance publication rather than a newly disclosed exploitation event.
CISA added newly identified XWiki and VMware vulnerabilities to its Known Exploited Vulnerabilities catalog, indicating evidence of active exploitation. The SC World reference reports this as the key development in the story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.