More than 28,000 unpatched Microsoft Exchange servers are publicly accessible and vulnerable to the critical security flaw CVE-2025-53786, as reported by The Shadowserver Foundation on August 7, 2025.

By infosecbulletin
/ Saturday , August 1 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
By infosecbulletin
/ Friday , July 31 2026
A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
By infosecbulletin
/ Friday , July 31 2026
Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
By infosecbulletin
/ Thursday , July 30 2026
NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
By infosecbulletin
/ Wednesday , July 29 2026
India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
By infosecbulletin
/ Tuesday , July 28 2026
CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
By infosecbulletin
/ Tuesday , July 28 2026
OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
By infosecbulletin
/ Tuesday , July 28 2026
ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
By infosecbulletin
/ Monday , July 27 2026
Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
By infosecbulletin
/ Monday , July 27 2026
Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
CISA’s Emergency Directive 25-02 on August 7 requires federal agencies to fix a critical vulnerability in Microsoft Exchange hybrid setups by 9:00 AM ET on August 11.
Vulnerability scans show that the US, Germany, and Russia have the most exposed vulnerable servers. These findings come as Microsoft and CISA warn of “significant, unacceptable risk” to organizations operating Exchange hybrid configurations that have not implemented the April 2025 security guidance.
The vulnerability originated on April 18, 2025, when Microsoft announced security changes for Exchange Server Hybrid Deployments along with a non-security hotfix.
The company recommends installing the April 2025 hotfix or later and making configuration changes in Exchange Server hybrid environments.
Security researcher Dirk-Jan Mollema from Outsider Security revealed a vulnerability at Black Hat USA 2025, showing how attackers can create forged authentication tokens that are valid for 24 hours, bypassing access policies.
Microsoft has labeled the vulnerability as “Exploitation More Likely” despite no confirmed active exploitation as of the disclosure date.
CISA Acting Director Madhu Gottumukkala highlighted the urgent need to address a vulnerability that poses a serious risk to crucial federal systems.
Organizations should apply the April 2025 Exchange Server hotfix updates, set up dedicated Exchange hybrid applications, and remove old service principal credentials.