The unfolding Hafnium attack is the latest event in the trend of cyber events. CISO’s are starting to recognize that enterprise cyber security is being redefined to mean me and all my suppliers, or the combination of first and third party cyber risk is enterprise risk. NotPetya demonstrated that breaching a small accounting firm could cost a firm like Merck over $1B in damage.
What lessons is the Hafnium attack teaching?
What Happened?
On Mar 2, threat actors attributed to a new Chinese APT Group, dubbed ‘Hafnium’ by Microsoft, exploited four Exchange server zero-day vulnerabilities. Industry participants have nearly uniformly reported this as a massive attack.
|
Observation Date |
March 10 |
March 8 |
March 11 |
March 11 |
March 15 |
|
Total Exchange Servers with OWA Observed |
320,000 |
Not avail |
400,000 |
Not avail |
18,000 |
|
Vulnerable IP’s |
100,000 |
125,000 |
82,000 |
68,500 |
2,500 |
|
Mapped Vulnerable Organizations |
14,000 |
Not avail |
Not Avail |
8,911 |
173 |
Where are we now?
In a March 15 update, Bitsight reported detecting over 300,000 Exchange servers, identifying nearly 65,000 that were vulnerable and over 14,000 (4%) that were still exploited. Twenty-one days after the attack was reported, the number of vulnerable systems has dramatically reduced indicating that organizations are steadily patching systems.
However, as of March 22, 28,500 vulnerable servers remain unpatched. But, patching alone does not remediate downloaded malicious files. The number of patched and exploited servers along with unpatched and exploited servers remains alarmingly high. These organizations are at risk of additional exploitation, including ransomware attacks. These organizations pose a digital supply chain threat to customers and partners relying on them for services.