On March 9, 2021 NYDFS issued another cybersecurity alert to regulated entities. It disclosed that in recent days thousands of organizations were compromised via zero-day (newly discovered) vulnerabilities in the Microsoft Exchange Server. Microsoft made patches available for these vulnerabilities on March 2 but many organizations apparently were compromised before the patches were either available or applied. NYDFS is urging all regulated entities with vulnerable Microsoft Exchange services to act immediately by patching or disconnecting vulnerable servers. CISA has also released a current activity update outlining how to search for the type of compromise identified.
The alert may be found here: https://www.dfs.ny.gov/reports_and_publications/press_releases/pr202103092