Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA and NSA Microsoft Exchange hardening guidance

Advisory/Mitigation
First reported
Last updated
Happening score
H score 10
2 unique sources, 2 articles

Summary

Hide ▲

CISA and NSA released Microsoft Exchange hardening guidance that pushes administrators to reduce attack surface, strengthen authentication, and retire unsupported servers before they become a breach path. The guidance targets on-premises and hybrid Exchange environments and emphasizes concrete mitigations rather than broad advice. It also reinforces protections for organizations still running end-of-life Exchange deployments after moving to Microsoft 365.

Related Happenings

Microsoft Exchange CVE-2026-42897 mitigation advisory

Advisory/Mitigation
First: 15.05.2026 12:40 Last: 15.05.2026 12:40 Sources 1

About this happening: **Microsoft** issued immediate mitigation guidance for **CVE-2026-42897**, reducing risk for **Exchange Server 2016, 2019, and Subscription Edition (SE)** on-premises servers that...

Latest development: 15.05.2026 15:35

Microsoft issued temporary mitigation guidance for CVE-2026-42897 while a patch is still in development, recommending the Exchange Emergency Mitigation (EM) Service, which is enabled by default and can be checked with the Exchange Health Checker script, or the Exchange On-premises Mitigation Tool (EOMT) for disconnected or air-gapped environments. Microsoft noted that the mitigations can disrupt features such as OWA Print Calendar and Inline images, and that servers older than March 2023 cannot receive new mitigations through EM Service.

Microsoft Exchange Server spoofing/XSS flaw under active exploitation (CVE-2026-42897)

Vulnerability
First: 15.05.2026 09:19 Last: 15.05.2026 09:19 Sources 1

About this happening: **CVE-2026-42897** is an **actively exploited** **spoofing/XSS** flaw in **on-premises Microsoft Exchange Server** that can let attackers trigger **arbitrary JavaScript** in a bro...

ICO releases five-step AI cyber guidance

Public Sector Action
First: 14.05.2026 12:00 Last: 14.05.2026 12:00 Sources 1

About this happening: The **UK Information Commissioner’s Office (ICO)** released a **five-step guide** urging organizations to prepare for **AI-powered cyber threats**, making it clear that stronger r...

CISA releases CI Fortify guidance for critical infrastructure resilience

Public Sector Action
First: 05.05.2026 15:00 Last: 05.05.2026 15:00 Sources 1

About this happening: CISA released CI Fortify, guidance for critical infrastructure operators across sectors to help keep essential services running during cyberattack or crisis conditions. The framew...

Latest development: 06.05.2026 16:15

CISA launched CI Fortify on Tuesday as a planning framework for critical infrastructure operators in water, energy, transportation and communications to prepare for cyber disruption by disconnecting OT systems from third-party and business networks, maintaining essential services in degraded communications conditions, and recovering compromised systems through backups, component replacement, or a transition to manual operations.

CISA-led zero-trust guide for OT environments

Public Sector Action
First: 30.04.2026 17:00 Last: 30.04.2026 17:00 Sources 1

About this happening: US government agencies led by **CISA** released **Adapting Zero Trust Principles to Operational Technology**, giving **OT operators** a framework to improve **critical infrastruct...

Timeline

  1. 30.10.2025 18:11 2 articles · 6mo ago

    CISA and NSA release Microsoft Exchange hardening guidance

    Initial Disclosure

    CISA and the NSA, joined by the Australian Cyber Security Centre and the Canadian Centre for Cyber Security, released guidance for IT administrators to harden Microsoft Exchange servers against attacks. The guidance recommends stronger user authentication and access controls, reduced application attack surface, stronger network encryption, keeping servers up to date, enabling emergency mitigation services, and retiring end-of-life on-premises or hybrid Exchange servers after moving to Microsoft 365.

    Show sources