10th Indian Delegation to Dubai, Gitex & Expand North Star – World’s Largest Startup Investor Connect
Tech

Chinese hackers exploit Microsoft flaw, gain access to US government email accounts

Microsoft has confirmed that a group of Chinese hackers exploited a vulnerability in its cloud email service, resulting in unauthorized access to the email accounts of US government employees. The hacking group, identified as Storm-0558, targeted approximately 25 email accounts, including those of government agencies and related consumer accounts linked to individuals associated with these organizations. Microsoft uses the nickname “Storm” to track emerging or developing hacking groups.

US Government Agencies Affected, Investigation Underway

Adam Hodge, a spokesperson for the White House’s National Security Council, confirmed that the breach impacted US government agencies, although Microsoft has not disclosed the specific government agencies affected. The State Department reportedly compromised and alerted Microsoft to the breach.

Method of Attack and Detection

Microsoft’s investigation revealed that Storm-0558, described as a well-resourced adversary based in China, gained access to email accounts by forging authentication tokens to exploit Outlook Web Access in Exchange Online (OWA) and Outlook.com. The hackers acquired a Microsoft consumer signing key to forge tokens, enabling access to OWA and Outlook.com. They then exploited a token validation issue to impersonate Azure AD users and gain entry to enterprise email accounts. The malicious activity went undetected for approximately a month until customers noticed abnormal mail activity and alerted Microsoft.

Focus on Espionage and Mitigation

Charlie Bell, Microsoft’s top cybersecurity executive, states that Storm-0558 appears to be an espionage-motivated adversary focused on intelligence collection. Microsoft successfully mitigated the attack, revoking Storm-0558’s access to the compromised accounts. However, it is unclear whether any sensitive data was exfiltrated during the month-long period of unauthorized access.

US Agencies Take Action and Encourage Reporting

The US Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory urging organizations to report any anomalous activity related to Microsoft 365. During a briefing, a senior FBI official described the intrusion as a targeted campaign affecting government agencies in single digits. A government-backed actor exfiltrated a limited amount of Exchange Online data, although the US government has not attributed the attack to China. CISA and the FBI emphasize the importance of promptly reporting any suspicious activity to their agencies.

Also Read The latest News:
Protest by Urban Company Service partners continues
Fintech startup OneStack raised $2 million in funds led by growX ventures and others

by Siliconluxembourg

Would-be entrepreneurs have an extra helping hand from Luxembourg’s Chamber of Commerce, which has published a new practical guide. ‘Developing your business: actions to take and mistakes to avoid’, was written to respond to  the needs and answer the common questions of entrepreneurs.  “Testimonials, practical tools, expert insights and presentations from key players in our ecosystem have been brought together to create a comprehensive toolkit that you can consult at any stage of your journey,” the introduction… Source link

by WIRED

B&H Photo is one of our favorite places to shop for camera gear. If you’re ever in New York, head to the store to check out the giant overhead conveyor belt system that brings your purchase from the upper floors to the registers downstairs (yes, seriously, here’s a video). Fortunately B&H Photo’s website is here for the rest of us with some good deals on photo gear we love. Save on the Latest Gear at B&H Photo B&H Photo has plenty of great deals, including Nikon’s brand-new Z6III full-frame… Source link

by Gizmodo

Long before Edgar Wright’s The Running Man hits theaters this week, the director of Shaun of the Dead and Hot Fuzz had been thinking about making it. He read the original 1982 novel by Stephen King (under his pseudonym Richard Bachman) as a boy and excitedly went to theaters in 1987 to see the film version, starring Arnold Schwarzenegger. Wright enjoyed the adaptation but was a little let down by just how different it was from the novel. Years later, after he’d become a successful… Source link