Really messy: Why the hack of Microsofts email system is getting worse

Author : harisjamals
Publish Date : 2021-03-10 06:32:43


Really messy: Why the hack of Microsofts email system is getting worse

A week after Microsoft announced that its widely used email server program had been hacked, experts are not encouraged by what they have found.

“In short, it's gotten really messy,” said Katie Nickels, the director of intelligence at the cybersecurity firm Red Canary. “We are seeing no signs of this slowing down.”

The cybersecurity community sprang into action after Microsoft first announced a series of vulnerabilities that let hackers break into the company's Exchange email and calendar programs. China has used it to spy on a wide range of industries in the United States ranging from medical research to law firms to defense contractors, the company said. China has denied responsibility.

But it hasn't stopped there. Microsoft's announcement has complicated the situation, with efforts to fix the flaws appearing to have drawn more hackers to exploit organizations that haven’t yet updated the software.

Nickels said she’d seen indications five different hacker groups, whose identities are unknown, were now exploiting it.

The list of victims is growing, said Ben Read, the director of threat analysis at the cybersecurity company Mandiant.

“It’s big,” he said. “We're above 40 incidents we're responding to, just current customers we have. We're at over 500 likely victims based on confirmation of likely sources.”

While there is no official, public list of victims, the full tally is “definitely in the tens of thousands,” Read said. “There's definitely a lot of small-, medium-sized entities. That's the customer base of Exchange.”

A White House National Security Council spokesperson said in an emailed statement that the Biden administration “is undertaking a whole-of-government response to assess and address the impact.”

“This is an active threat still developing,” the spokesperson said.
Recommended
Security
'Really messy': Why the hack of Microsoft's email system is getting worse
Security
U.S. issues warning after Microsoft says China hacked its mail server program

While there have been no reports so far that any government agencies have been affected, the U.S. Cybersecurity and Infrastructure Security Agency, the country's primary cybersecurity agency, on Wednesday exercised its emergency powers to force government agencies to update to the latest version of Exchange.

In an unusually candid message, the agency then tweeted Monday evening that “CISA urges ALL organizations across ALL sectors to follow guidance to address the widespread domestic and international exploitation of Microsoft Exchange Server product vulnerabilities.”
The hack started quietly, as a more surgical operation. Initially, the only hackers exploiting Exchange were the ones Microsoft identified as Chinese spies, sometime around the beginning of the year, researchers say.

Near the end of January, the cybersecurity company Volexity noticed hackers spying on two of its customers and alerted Microsoft so it could begin working on a fix in its next Exchange software update.

“They were using that explicitly to steal emails,” Volexity President Steven Adair said in a phone call. “It was under the radar.”

Adair said that after he told Microsoft, he noticed a change in the hackers’ activity: They seemed to realize a patch was coming, so they moved from stealthily reading emails to trying to create footholds to stay in their victims’ networks, which made them far more visible to cybersecurity defenders.

Releted Topics:

https://pbea.agron.iastate.edu/users/watch-flash-season-7-episode-2-full-episodes-0
https://pbea.agron.iastate.edu/access/4438/watch-flash-season-7-episode-2-full-episodes-0
https://pbea.agron.iastate.edu/users/full-watch-flash-season-7-episode-2-full-episodes
https://pbea.agron.iastate.edu/access/4441/full-watch-flash-season-7-episode-2-full-episodes
https://pbea.agron.iastate.edu/users/superman-and-lois-season-1-episode-3-full-episodes



Category : general

More control will improve the amount of tension there is on the muscle. The more time-under tension the muscle is under,

More control will improve the amount of tension there is on the muscle. The more time-under tension the muscle is under,

- The second development to watch for is the inevitable release of additional and more powerful Apple processors. The M1 name itself suggests that more processors will be coming, and we expect Apple Sil


A Review Of Approved AZ-204 Free Demo

A Review Of Approved AZ-204 Free Demo

- A Review Of Approved AZ-204 Free Demo,A Review Of Approved AZ-204 Free Demo


Guide To Clear Microsoft PL-200 Certification Exam

Guide To Clear Microsoft PL-200 Certification Exam

- Not long in the past, I had been speaking with an extremely amazing lady who had been an administrator within a Company at


Tips For Passing Salesforce CRT-550 Certification Exam

Tips For Passing Salesforce CRT-550 Certification Exam

- Today, there is a lot of hype about Search Engine Optimisation. Men and women which have been trying to get to get a no cost of demand