Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • Technology

Chinese hackers raided US government email accounts by exploiting Microsoft cloud bug

  • July 12, 2023
Total
0
Shares
0
0
0

Chinese hackers exploited a flaw in Microsoft’s cloud email service to gain access to the email accounts of U.S. government employees, the technology giant has confirmed.

The hacking group, tracked as Storm-0558, compromised approximately 25 email accounts, including government agencies, as well as related consumer accounts linked to individuals associated with these organizations, according to Microsoft. “Storm” is a nickname used by Microsoft to track hacking groups that are new, emerging or “in development.”

Microsoft has not identified the government agencies targeted by Storm-0558. However, Adam Hodge, a spokesperson for the White House’s National Security Council, confirmed to TechCrunch that U.S. government agencies were affected.

“Last month, U.S. government safeguards identified an intrusion in Microsoft’s cloud security, which affected unclassified systems,” Hodge told TechCrunch in a statement. “Officials immediately contacted Microsoft to find the source and vulnerability in their cloud service. We continue to hold the procurement providers of the U.S. Government to a high security threshold.

Microsoft’s investigation determined that Storm-0558, a China-based hacking group that the firm describes as a “well-resourced” adversary, gained access to email accounts using Outlook Web Access in Exchange Online (OWA) and Outlook.com by forging authentication tokens to access user accounts. In its technical analysis of the attack, Microsoft explained that the hackers used an acquired Microsoft consumer signing key to forge tokens to access OWA and Outlook.com. Then, the hackers exploited a token validation issue to impersonate Azure AD users and gain access to enterprise email accounts.

Storm-0885’s malicious activity had gone undetected for about a month until customers alerted Microsoft to anomalous mail activity, Microsoft said.

“We assess this adversary is focused on espionage, such as gaining access to email systems for intelligence collection. This type of espionage-motivated adversary seeks to abuse credentials and gain access to data residing in sensitive systems”, said Charlie Bell, Microsoft’s top cybersecurity executive.

Microsoft said the attack was successfully mitigated and that Storm-0558 no longer has access to the compromise accounts. However, the company has not said whether any sensitive data was exfiltrated over the month-long period that the attackers had access.


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

When does Amazon Prime Day end – and is it really the end?

  • July 12, 2023
View Post
Next Article
  • Technology

Voice cloning platform Resemble AI lands $8M

  • July 12, 2023
View Post
You May Also Like
View Post
  • Technology

Tiny EV maker ElectraMeccanica pulls the plug on its exit plan

  • October 4, 2023
View Post
  • Technology

Bird lays off staff after Spin acquisition to reduce redundancies

  • October 4, 2023
View Post
  • Technology

Patreon launches new features, a redesigned app and a new look

  • October 4, 2023
View Post
  • Technology

Microsoft won’t say if its products were exploited by spyware zero-days

  • October 4, 2023
View Post
  • Technology

Walmart experiments with new generative AI tools that can help you plan a party or decorate a space

  • October 4, 2023
View Post
  • Technology

What’s at stake in the Supreme Court’s landmark social media case

  • October 4, 2023
View Post
  • Technology

Investors still not enthusiastic about the massive Cisco-Splunk deal

  • October 4, 2023
View Post
  • Technology

Actually, X sees 500M posts per day — not 100M-200M as Musk recently said

  • October 4, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.