• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
microsoft exchange admin portal taken offline due to forgotten certificate

Microsoft Exchange admin portal taken offline due to forgotten certificate

You are here: Home / General Cyber Security News / Microsoft Exchange admin portal taken offline due to forgotten certificate
May 24, 2021

Microsoft’s Exchange administration portal was offline above the weekend after the business unsuccessful to renew an expired SSL/TLS certificate.

Bleeping Laptop or computer noted that Trade administrators were being unable to entry the website on Sunday early morning. They encountered an error webpage outlining that their relationship was not private. At the time, Qualys Labs described the certification involved with the web page expired at 8 a.m. Japanese Time on Sunday, but Microsoft has considering the fact that preset the issue.

Twitter person Tzatl tweeted at the organization on Sunday, inquiring, “Did you guys actually ignore to renew a certificate?” Microsoft responded that it experienced isolated the problem and was making use of a take care of, referring buyers to entry EX257883 beneath its company overall health dashboard.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The issue provoked some teasing from people on Twitter. “Another person carried out goofed,” replied 1 person, alongside with a picture of the untrusted certification report from Digicert Cloud Companies.

This isn’t really the to start with time a substantial technology organization has downed a assistance by forgetting to renew a certification. 

Previous month, Epic Games unintentionally permitted a certification employed across quite a few of its internal-facing providers to expire. That took account logins offline for numerous of its most well known games, including Fortnite. In February, Google Voice went offline temporarily after a certificate went out of day. In November, GitHub’s house page went down just after a certificate dependable for accessing details from a articles distribution network expired. Very last August, Spotify let a TLS certificate lapsed, leaving users without the need of music.

Safe Socket Layer (SSL) has evolved into its successor, Transport Layer Security (TLS). Both of those are cryptographic protocols that present protected connections involving two endpoints. An SSL/TLS certification enables a website to prove its identification with a dependable third-party certificate authority (CA).

Certification management is probable to become a lot more problematic next a transform to certificate longevity very last September. Apple, Google, and Mozilla all imposed a optimum 398-day lifetime on certificates from September 1, 2020 in a bid to limit the time a web page can use a compromised certification. This carries on a craze of shortening certification lifespans, which stood at 60 months in 2012, 39 months in 2015, and 27 months in 2018. 

In its 2021 Point out of Equipment Id Administration Report, Keyfactor located that 88% of corporations had knowledgeable at minimum just one unplanned certification outage in the prior two several years.


Some elements of this report are sourced from:
www.itpro.co.uk

Previous Post: «researchers link cryptocore attacks on cryptocurrency exchanges to north korea Researchers Link CryptoCore Attacks On Cryptocurrency Exchanges to North Korea
Next Post: Restaurant Reservation System Patches Easy-to-Exploit XSS Bug restaurant reservation system patches easy to exploit xss bug»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.