A Busy Stretch for Business Software Security
Three separate companies made major security announcements this week, and while most of the details involve business software rather than the apps on your phone, the changes affect a huge number of organizations that everyday people rely on, from employers to email providers to cloud services. Oracle, Microsoft, and Zimbra each addressed serious security problems in their products, and the scale of one of these updates in particular is worth understanding.
Oracle's Massive Patch Batch
Oracle released its quarterly security update this month, and the number of fixes involved is striking. More than 1,400 individual vulnerabilities were addressed across Oracle's various products, which include software used by banks, retailers, hospitals, and government agencies around the world.
Security researchers believe a good portion of these flaws were found with help from artificial intelligence tools. AI systems are increasingly being used to scan huge amounts of code for weaknesses that would take human researchers far longer to spot. That means bug hunting is speeding up, which is good news for security in the long run, but it also means companies like Oracle need to keep pace with a faster stream of discoveries.
For regular users, the direct impact is limited since Oracle's products mostly run behind the scenes at the businesses you interact with. Still, when a company you do business with delays patching, it can leave your personal data sitting on a vulnerable system for longer than it should.
Microsoft Sets a Deadline for Exchange 2016 and 2019
Microsoft has confirmed that security updates for Exchange Server 2016 and Exchange Server 2019 will stop this October under its Extended Security Update program. This program was designed to give organizations extra time to move off older software, but that extra time is now running out.
Exchange Server is widely used by companies and institutions to manage internal email systems. Once these versions stop receiving security patches, any newly discovered vulnerabilities will remain unfixed, making them easier targets for hackers looking to break into corporate networks. Attacks on email servers are especially damaging because they often serve as a gateway to everything else in an organization, including employee accounts, financial records, and customer data.
If your workplace, school, or any organization you deal with uses Exchange Server, this deadline matters. Systems left unpatched after the cutoff become considerably easier to break into, and a breach at one of these organizations can expose the personal information of anyone whose data they store, including customers and clients.
Zimbra Closes a Serious Email Server Gap
Zimbra, another popular email and collaboration platform used by businesses and organizations, released a security update fixing nine vulnerabilities in its software. The most serious of these was a command injection flaw tied to a network monitoring feature called SNMP.
In simple terms, this flaw could have allowed an attacker to run unauthorized commands on a Zimbra server if a certain monitoring setting was turned on. That kind of access could let a hacker take control of the system, read private emails, or use the server as a launching point for further attacks. Zimbra also fixed four separate cross-site scripting issues, which are commonly used to trick a user's browser into running malicious code or stealing session information.
The fixed version, Zimbra 10.1.20, is now available, and organizations running the software are being urged to update quickly given how serious the command injection bug is.
Why This Matters Even If You Don't Manage Servers
Most people will never log into Oracle, Exchange, or Zimbra directly, but these systems often sit behind the websites, apps, and services people use every day. When a company delays applying a patch, or keeps running software that no longer receives security updates, it creates an opening that hackers are quick to exploit. Breaches at organizations using outdated or unpatched systems are a common source of the data leaks that eventually affect ordinary account holders and customers.
- If you work for a company that uses Exchange Server 2016 or 2019, ask your IT department about their upgrade timeline before the October cutoff.
- If your organization runs Zimbra, confirm that it has been updated to version 10.1.20 or later.
- Keep an eye out for breach notification emails from services you use, since incidents tied to outdated business software often surface weeks or months later.
- As always, use unique passwords for different accounts and turn on two factor authentication where it's offered, so a breach at one company doesn't compromise your other accounts.