Microsoft issues emergency software patches for four zero-day vulnerabilities in its Exchange email server. The company says it believes the flaws have been exploited by a China-based group it calls Hafnium. The group has been targeting infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks and nongovernment organizations. The vulnerabilities only affect the on-premises version of Exchange, where an organization has chosen to host the application itself; it does not affect Exchange online or the cloud version.”]
Source: https://www.healthcareinfosecurity.com/microsoft-patches-four-zero-day-flaws-in-exchange-a-16098

