Categories: World

Chinese hackers hit 30K US organisations in new attack

<p>
<strong>In yet another big cyber-attack after SolarWinds, at least 30,000 organisations across the US, including government and commercial firms, have been hacked by China-based threat actors who used Microsoft's Exchange Server software to enter their networks.</strong></p>
<p>
According to KrebsOnSecurity, the China-based espionage group exploited four vulnerabilities in Microsoft Exchange Server email software.</p>
<p>
The vulnerabilities allowed hackers to gain access to email accounts, and also gave them the ability to install malware, according to Microsoft which reported about the China-based threat actors but did not reveal the scale at which tens of thousands of organisations have been hit.</p>
<p>
Two cybersecurity experts who have briefed US national security advisors on the attack told KrebsOnSecurity the Chinese hacking group seized control over "hundreds of thousands" of Microsoft Exchange Servers worldwide.</p>
<p>
Exchange Server is primarily used by business customers.</p>
<p>
Microsoft has released several security updates to fix the vulnerabilities, advising its customers to install those immediately.</p>
<p>
Earlier this week, Microsoft warned its customers against a new sophisticated nation-state cyber-attack that has its origin in China and is primarily targeting on-premises 'Exchange Server' software of the tech giant.</p>
<p>
Called "Hafnium," it operates from China and is attacking infectious disease researchers, law firms, higher education institutions, defence contractors, policy think tanks and NGOs in the US for the purpose of exfiltrating information.</p>
<p>
"While Hafnium is based in China, it conducts its operations primarily from leased virtual private servers (VPS) in the US," said Tom Burt, Corporate Vice President, Customer Security and Trust at Microsoft.</p>
<p>
This was the eighth time in the past 12 months that Microsoft has publicly disclosed nation-state groups targeting institutions critical to civil society.</p>
<p>
Nine federal agencies and about 100 private sector companies were compromised as a result of an earlier SolarWinds hack, the White House had said.</p>
<p>
In a widespread cyber-attack on US federal agencies and enterprises via SolarWinds software, hackers also broke into the networks of NASA and the Federal Aviation Administration (FAA).</p>
<p>
The Joe Biden administration was preparing sanctions against Russia as the cybercriminals are "likely Russian in origin".</p>
<p>
<em>(IANS)</em></p>
<p>
 </p>
<p>
 </p>
<p>
 </p>
<p>
 </p>
<p>
 </p>

India Narrative

Recent Posts

WHO congratulates South East Asia for its polio eradication achievements on World Polio Day

Saima Wazed, World Health Organisation's (WHO) Regional Director for South-East Asia, on Thursday congratulated the…

3 hours ago

“Broad consensus has been achieved”: Defence Minister Rajnath Singh on India-China truce at LAC

Defence Minister Rajnath Singh in the 'Chanakya Defence Dialogue' on India-China disengagement asserted that broad…

4 hours ago

PoGB: Protests over Sarfaranga Cold Desert land ruling cross one-month mark

The situation in the Shigar district of Pakistan-occupied Gilgit-Baltistan remains tense as residents continue their…

4 hours ago

Tibetan rights group demand China to reveal location of detained monks

The Tibetan Centre for Human Rights and Democracy (TCHRD) has urgently called on Chinese authorities…

4 hours ago

Cabinet approves Rs 6,798 crore projects to boost connectivity, cut logistics costs, and reduce CO2 emissions in 5 years

The Cabinet Committee on Economic Affairs (CCEA) chaired by the Prime Minister Narendra Modi, has…

6 hours ago

“India will be biggest intelligence market” says Mukesh Ambani as Reliance-NVIDIA partner to build cutting-edge AI infra

To strengthen India's artificial intelligence (AI) capabilities, Jensen Huang, CEO of NVIDIA announced a partnership…

6 hours ago