Unpatched Exchange Servers an overlooked risk

The US Cybersecurity and Infrastructure Security Agency (CISA) has started a list of what it deems to be bad security practices. The two on the list so far instruct any organization that provides national critical functions (NCF) what not to do. They are so broad in their “badness,” however, that any organization should take notice and ensure they are not doing them. The two bad practices are:

  1. Use of unsupported (or end-of-life) software
  2. Use of known/fixed/default passwords and credentials

