ShiftDelete.Net Global

One Hybrid Exchange Flaw Could Undermine Cloud Identity Security

Ana sayfa / News

Microsoft has confirmed a serious flaw in hybrid Exchange setups that could let hackers move from on-prem servers into cloud environments without being seen. This vulnerability, tagged CVE‑2025‑53786, has big implications for identity safety.

At the core of the issue is a shared identity connection between Exchange Online and on-prem servers. When this bridge is exploited, attackers with admin access can fake tokens or cloud calls, skipping logs entirely. As a result, they can gain wide access to systems without leaving behind a trace.

Microsoft Windows 11 dev channel enters next testing phase

Microsoft begins testing Windows 11’s next phase in the Dev Channel, launching new 26000-series builds with foundational platform changes.

To stay safe, Microsoft recommends immediate action:

In addition, CISA now demands that U.S. agencies disconnect unsupported on-prem Exchange or SharePoint servers from the internet. Agencies must patch vulnerable setups before August 15.

Unlike most hacks, this one doesn’t need malware. It uses trust. Since cloud systems still “trust” old hybrid links, a skilled attacker can slip past modern defenses. This puts identity, email, and admin roles at risk.

Hybrid setups were designed to help move users to the cloud. But in this case, they create a quiet path for attacks. And that path is built on outdated trust that few people think to check.

Moving forward, shared trust models won’t cut it. As Microsoft shifts to better defenses, companies must drop legacy paths before they’re used against them.

Yorum Ekleyin