Forum Discussion
hafnium attack | exchange iapp
APM seems like the way to go, if you add authentication before traffic reaching the Exchange server you have a good protection.
it remains kinda unclear in which path the attacks focus, this website suggests one. but things move quickly probably.
https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/
- boneyardMar 06, 2021
MVP
if you have ASM / AWAF this is useful to check:
https://devcentral.f5.com/s/articles/HAFNIUM-APT-Group-Exploiting-Microsoft-Exchange-Vulnerabilities
- Abed_AL-RMar 07, 2021
Cirrostratus
Thank you boneyard :) Great articles
We do have the APM along with 2fa on the OWA
we'll check also the ASM option
I saw also that DevCentral published ASM template to have OWA in blocking mode from day one
https://devcentral.f5.com/s/articles/new-asm-outlook-web-access-owa-2016-template-for-bigip-v13-29413
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
