Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Miscreants Manipulate Mimecast Certificate -> Microsoft 365 Exchange Web Services: Welcome To The Pew Pew

January 13, 2021 by Marc Handelman in Certificates, Certificate Theft, Certificate Manipulation, Information Security, Cyber Miscreants

In regards to connectivity to the security black hole, also known as Microsoft Corporation's Office 365. Microsoft Corporation claims nothing to see here.

'Approximately 10 percent of our customers use this connection. Of those that do, there are indications that a low single digit number of our customers’ M365 tenants were targeted. We have already contacted these customers to remediate the issue. As a precaution, we are asking the subset of Mimecast customers using this certificate-based connection to immediately delete the existing connection within their M365 tenant and re-establish a new certificate-based connection using the new certificate we’ve made available. Taking this action does not impact inbound or outbound mail flow or associated security scanning.' - via Mimecast et al.

January 13, 2021 /Marc Handelman
Certificates, Certificate Theft, Certificate Manipulation, Information Security, Cyber Miscreants
  • Newer
  • Older