• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
microsoft exchange admin portal taken offline due to forgotten certificate

Microsoft Exchange admin portal taken offline due to forgotten certificate

You are here: Home / General Cyber Security News / Microsoft Exchange admin portal taken offline due to forgotten certificate
May 24, 2021

Microsoft’s Exchange administration portal was offline above the weekend after the business unsuccessful to renew an expired SSL/TLS certificate.

Bleeping Laptop or computer noted that Trade administrators were being unable to entry the website on Sunday early morning. They encountered an error webpage outlining that their relationship was not private. At the time, Qualys Labs described the certification involved with the web page expired at 8 a.m. Japanese Time on Sunday, but Microsoft has considering the fact that preset the issue.

Twitter person Tzatl tweeted at the organization on Sunday, inquiring, “Did you guys actually ignore to renew a certificate?” Microsoft responded that it experienced isolated the problem and was making use of a take care of, referring buyers to entry EX257883 beneath its company overall health dashboard.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The issue provoked some teasing from people on Twitter. “Another person carried out goofed,” replied 1 person, alongside with a picture of the untrusted certification report from Digicert Cloud Companies.

This isn’t really the to start with time a substantial technology organization has downed a assistance by forgetting to renew a certification. 

Previous month, Epic Games unintentionally permitted a certification employed across quite a few of its internal-facing providers to expire. That took account logins offline for numerous of its most well known games, including Fortnite. In February, Google Voice went offline temporarily after a certificate went out of day. In November, GitHub’s house page went down just after a certificate dependable for accessing details from a articles distribution network expired. Very last August, Spotify let a TLS certificate lapsed, leaving users without the need of music.

Safe Socket Layer (SSL) has evolved into its successor, Transport Layer Security (TLS). Both of those are cryptographic protocols that present protected connections involving two endpoints. An SSL/TLS certification enables a website to prove its identification with a dependable third-party certificate authority (CA).

Certification management is probable to become a lot more problematic next a transform to certificate longevity very last September. Apple, Google, and Mozilla all imposed a optimum 398-day lifetime on certificates from September 1, 2020 in a bid to limit the time a web page can use a compromised certification. This carries on a craze of shortening certification lifespans, which stood at 60 months in 2012, 39 months in 2015, and 27 months in 2018. 

In its 2021 Point out of Equipment Id Administration Report, Keyfactor located that 88% of corporations had knowledgeable at minimum just one unplanned certification outage in the prior two several years.


Some elements of this report are sourced from:
www.itpro.co.uk

Previous Post: «researchers link cryptocore attacks on cryptocurrency exchanges to north korea Researchers Link CryptoCore Attacks On Cryptocurrency Exchanges to North Korea
Next Post: Restaurant Reservation System Patches Easy-to-Exploit XSS Bug restaurant reservation system patches easy to exploit xss bug»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks
  • Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets
  • Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns
  • Chinese Hackers Use Anthropic’s AI to Launch Automated Cyber Espionage Campaign
  • Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts
  • Russian Hackers Create 4,300 Fake Travel Sites to Steal Hotel Guests’ Payment Data
  • Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
  • When Attacks Come Faster Than Patches: Why 2026 Will be the Year of Machine-Speed Security
  • Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown
  • ThreatsDay Bulletin: Cisco 0-Days, AI Bug Bounties, Crypto Heists, State-Linked Leaks and 20 More Stories

Copyright © TheCyberSecurity.News, All Rights Reserved.