{"id":72835,"date":"2025-08-10T17:51:09","date_gmt":"2025-08-10T17:51:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/72835\/"},"modified":"2025-08-10T17:51:09","modified_gmt":"2025-08-10T17:51:09","slug":"emergency-microsoft-security-warning-confirmed-act-now-cisa-says","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/72835\/","title":{"rendered":"Emergency Microsoft Security Warning Confirmed \u2014 Act Now, CISA Says"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us\/wp-content\/uploads\/2025\/08\/1754848269_881_960x0.jpg\" alt=\"Microsoft Office Building in New York City\" data-height=\"1983\" data-width=\"3186\" style=\"position:absolute;top:0\"\/><\/p>\n<p>CISA issues Microsoft Exchange Server CVE-2025-53786 warning<\/p>\n<p>Getty Images<\/p>\n<p>Update, August 10, 2025: This story, originally published on August 7, has been updated with additional information following a demonstration of the shared service principal exploit at the Black Hat hacking conference in Las Vegas, which, in turn, follows a Microsoft Exchange vulnerability directive issued by CISA. Details of a newly announced protection that adds to the Microsoft Defender security arsenal have also been added to the article. <\/p>\n<p>Hot on the heels of an official security advisory from America\u2019s Cyber Defense Agency warning of <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/06\/camera-hacks-ongoing---americas-cyber-defense-agency-confirms\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/06\/camera-hacks-ongoing---americas-cyber-defense-agency-confirms\/\" target=\"_self\" aria-label=\"camera hack attacks\" rel=\"nofollow noopener\">camera hack attacks<\/a>, the U.S. Cybersecurity and Infrastructure Security Agency has issued another alert. This time, it impacts users of Microsoft Exchange Server and, without immediate remediation, could enable an attacker to escalate privileges and \u201cimpact the identity integrity of an organization\u2019s Exchange Online service.\u201d But it\u2019s not all bad news on the Microsoft security front; the technology giant has confirmed new AI-powered protections to autonomously reverse engineer and classify malware, importantly, without any prior context requirement. Here\u2019s what you need to know.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-6\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/09\/now-google-warns-of-cloud-hack-attacks---3-steps-you-must-take\/\" target=\"_blank\" aria-label=\"Google Cloud Hack Attack Confirmed \u2014 Do These 3 Things Now\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/09\/now-google-warns-of-cloud-hack-attacks---3-steps-you-must-take\/\" rel=\"nofollow noopener\">ForbesGoogle Cloud Hack Attack Confirmed \u2014 Do These 3 Things NowBy Davey Winder<\/a><\/p>\n<p>CISA And Microsoft Warn Users Of CVE-2025-53786 Attack Danger<\/p>\n<p>There have been a number of security warnings impacting Microsoft users of late that may have caught your attention: the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/04\/microsoft-windows-is-being-hacked-if-you-see-these-jpeg-images\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/04\/microsoft-windows-is-being-hacked-if-you-see-these-jpeg-images\/\" target=\"_self\" aria-label=\"Windows JPEG hackers\" rel=\"nofollow noopener\">Windows JPEG hackers<\/a> and, of course, the by now infamous <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/21\/microsoft-confirms-ongoing-mass-sharepoint-attack---no-patch-available\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/21\/microsoft-confirms-ongoing-mass-sharepoint-attack---no-patch-available\/\" target=\"_self\" aria-label=\"SharePoint Server attacks\" rel=\"nofollow noopener\">SharePoint Server attacks<\/a> to name but two. The very latest, however, comes with the added weight of a CISA alert attached.<\/p>\n<p>\u201cCISA is aware of the newly disclosed high-severity vulnerability, CVE-2025-53786,\u201d the <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/08\/06\/microsoft-releases-guidance-high-severity-vulnerability-cve-2025-53786-hybrid-exchange-deployments\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/08\/06\/microsoft-releases-guidance-high-severity-vulnerability-cve-2025-53786-hybrid-exchange-deployments\" aria-label=\"August 6 advisory\">August 6 advisory<\/a> warned, \u201cthat allows a cyber threat actor with administrative access to an on-premise Microsoft Exchange server to escalate privileges by exploiting vulnerable hybrid-joined configurations.\u201d<\/p>\n<p>Microsoft, meanwhile, has <a class=\"color-link\" href=\"https:\/\/techcommunity.microsoft.com\/blog\/exchange\/dedicated-hybrid-app-temporary-enforcements-new-hcw-and-possible-hybrid-function\/4440682\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/techcommunity.microsoft.com\/blog\/exchange\/dedicated-hybrid-app-temporary-enforcements-new-hcw-and-possible-hybrid-function\/4440682\" aria-label=\"said\">said<\/a> that \u201cstarting in August 2025, we will begin temporarily blocking Exchange Web Services traffic using the Exchange Online shared service principal,\u201d as part of a \u201cphased strategy to speed up customer adoption of the dedicated Exchange hybrid app and making our customers\u2019 environments more secure.\u201d<\/p>\n<p>Although CISA confirmed that there has not been any observed active exploitation of CVE-2025-53786, it strongly urged organizations to follow the Microsoft guidance on this issue.<\/p>\n<p>CVE-2025-53786 is officially listed as a Microsoft Exchange Server Hybrid Deployment elevation of privilege vulnerability that follows an accompanying non-security hot fix when the hybrid deployments were announced on April 18. \u201cFollowing further investigation,\u201d the official Common Vulnerabilities and Exposures database entry reads, \u201cMicrosoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement.\u201d<\/p>\n<p>CISA added that it \u201chighly recommends entities disconnect public-facing versions of Exchange Server or SharePoint Server that have reached their end-of-life (EOL) or end-of-service from the internet.\u201d<\/p>\n<p> <a class=\"embed-base color-body color-body-border link-embed embed-7\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/warning-windows-hello-security-bypassed-using-other-peoples-faces\/\" target=\"_blank\" aria-label=\"Microsoft Windows Security Bypass \u2014 Hello Hackers Use Own Faces\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/warning-windows-hello-security-bypassed-using-other-peoples-faces\/\" rel=\"nofollow noopener\">ForbesMicrosoft Windows Security Bypass \u2014 Hello Hackers Use Own FacesBy Davey Winder<\/a><br \/>\nMicrosoft Shared Service Principal Exploit Demonstrated At Black Hat Hacking Conference In Las Vegas<\/p>\n<p>A researcher from Outsider Security, Dirk-Jan Mollema, has now demonstrated how the shared service principal behind the latest CISA advisory and directive can be exploited. The demonstration, during a presentation at the Black Hat hacking conference in Las Vegas, went ahead after Microsoft was informed of its contents three weeks prior, Mollema told reporters from the <a class=\"color-link\" href=\"https:\/\/A researcher from Outsider Security, Dirk-Jan Mollema, has now demonstrated how the shared service principal behind the latest CISA advisory and directive can be exploited. The demonstration, during a presentation at the Black Hat hacking conference in Las Vegas, went ahead after Microsoft was informed of its contents three weeks prior, Mollema told reporters from the Bleeping Computer cybersecurity site.  https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-orders-fed-agencies-to-patch-new-cve-2025-53786-exchange-flaw\/. As a result, the CVE-2025-53786 classification was made, and Microsoft issued the aforementioned mitigation guidance.   &quot;The report describing the possibilities for attackers was sent as a heads up to the Microsoft Security Response Center three weeks before Black Hat,\u201d Mollema confirmed, adding that \u201caside from this guidance Microsoft also mitigated an attack path that could lead to full tenant compromise (Global Admin) from on-prem Exchange.&quot;\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/A researcher from Outsider Security, Dirk-Jan Mollema, has now demonstrated how the shared service principal behind the latest CISA advisory and directive can be exploited. The demonstration, during a presentation at the Black Hat hacking conference in Las Vegas, went ahead after Microsoft was informed of its contents three weeks prior, Mollema told reporters from the Bleeping Computer cybersecurity site.  https:\/\/www.bleepingcomputer.com\/news\/security\/cisa-orders-fed-agencies-to-patch-new-cve-2025-53786-exchange-flaw\/. As a result, the CVE-2025-53786 classification was made, and Microsoft issued the aforementioned mitigation guidance.   &quot;The report describing the possibilities for attackers was sent as a heads up to the Microsoft Security Response Center three weeks before Black Hat,\u201d Mollema confirmed, adding that \u201caside from this guidance Microsoft also mitigated an attack path that could lead to full tenant compromise (Global Admin) from on-prem Exchange.&quot;\" aria-label=\"Bleeping Computer\">Bleeping Computer<\/a> cybersecurity site. As a result, the CVE-2025-53786 classification was made, and Microsoft issued the aforementioned mitigation guidance. &#8220;The report describing the possibilities for attackers was sent as a heads up to the Microsoft Security Response Center three weeks before Black Hat,\u201d Mollema confirmed, adding that \u201caside from this guidance Microsoft also mitigated an attack path that could lead to full tenant compromise (Global Admin) from on-prem Exchange.&#8221;<\/p>\n<p>The shared service principle being that, at least in such hybrid configurations as relevant to the Microsoft Exchange warning, both Exchange Online and on-premises servers share a relationship of trust that allows them to, supposedly securely, authenticate with each other. As the Black demonstration showed, provided the attacker has admin privileges for the on-premise Exchange server, so-called trusted tokens can be forged, and API calls manipulated, so as to appear perfectly legitimate as far as the cloud side of the authentication equation is concerned.<\/p>\n<p>In speaking to Bleeping Computer, Mollema said that installing the Microsoft Hotfix alone would not be enough to mitigate the risk of these attacks, and that \u201cthere are manual follow-up actions required to migrate to a dedicated service principal.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/google-confirms-it-has-been-hacked---user-data-stolen\/\" target=\"_blank\" aria-label=\"Confirmed: Google Has Been Hacked \u2014 User Data Compromised\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/08\/google-confirms-it-has-been-hacked---user-data-stolen\/\" rel=\"nofollow noopener\">ForbesConfirmed: Google Has Been Hacked \u2014 User Data CompromisedBy Davey Winder<\/a><br \/>\nMicrosoft Announces Project Ire, Calling It The Gold Standard In AI Malware Classification<\/p>\n<p>To balance the Microsoft security news scales a little, it has also been announced that a new \u201cautonomous AI agent that can analyze and classify software without assistance.\u201d In other words, fully reverse engineer a software file in order to classify potential malware and do so without \u201cany clues about its origin or purpose.\u201d Something that, Microsoft said, is not only a step forward in cybersecurity and malware detection, but also the gold standard in malware classification.<\/p>\n<p><a class=\"color-link\" href=\"https:\/\/www.microsoft.com\/en-us\/research\/blog\/project-ire-autonomously-identifies-malware-at-scale\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.microsoft.com\/en-us\/research\/blog\/project-ire-autonomously-identifies-malware-at-scale\/\" aria-label=\"Project Ire\">Project Ire<\/a>, born out of Microsoft Research, Microsoft Defender Research and the Microsoft Discovery &amp; Quantum teams working together, uses decompilers alongside other tools to determine whether the software in question is malicious or not. \u201cThe system uses advanced language models and a suite of callable reverse engineering and binary analysis tools to drive investigation and adjudication,\u201d Microsoft said. And does so, according to Microsoft\u2019s figures, with a 0.08 precision rate using public datasets of Windows drivers.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-8\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/06\/camera-hacks-ongoing---americas-cyber-defense-agency-confirms\/\" target=\"_blank\" aria-label=\"Camera Hacking  \u2014 America\u2019s Cyber Defense Agency Issues Warning\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/06\/camera-hacks-ongoing---americas-cyber-defense-agency-confirms\/\" rel=\"nofollow noopener\">ForbesCamera Hacking  \u2014 America\u2019s Cyber Defense Agency Issues WarningBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"CISA issues Microsoft Exchange Server CVE-2025-53786 warning Getty Images Update, August 10, 2025: This story, originally published on&hellip;\n","protected":false},"author":2,"featured_media":72836,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[28,31948,52132,52127,52131,52128,52129,52130],"class_list":["post-72835","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-business","tag-cisa","tag-cisa-warning","tag-cve-2025-53786","tag-microsoft-exchange","tag-microsoft-exchange-server","tag-microsoft-security-warning","tag-microsoft-server"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/72835","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=72835"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/72835\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/72836"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=72835"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=72835"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=72835"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}