Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Microsoft: 4 Exchange Server Zero-Days Under Attack by Chinese Hacking Group
security week ^ | 3/2/2021 | Ryan Naraine

Posted on 03/02/2021 3:47:35 PM PST by bitt

Microsoft late Tuesday raised the alarm after discovering Chinese cyber-espionage operators chaining multiple zero-day exploits to siphon e-mail data from corporate Microsoft Exchange servers.

Redmond's warning includes the release of emergency out-of-band patches for four distinct zero-day vulnerabilities that formed part of the threat actor's arsenal.

Microsoft pinned the blame on a sophisticated Chinese APT operator called HAFNIUM that operates from leased VPS (virtual private servers) in the United States.

HAFNIUM primarily targets entities in the U.S. across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.

The company said its analysts assess with high confidence that HAFNIUM is state-sponsored and operating out of China, based on observed victimology, tactics and procedures.

In all, Microsoft said the attacker chained four zero-days into a malware cocktail targeting its Exchange Server (Outlook Web App) product. The vulnerabilities exposed Microsoft's customers to remote code excecution attacks, without requiring authentication.

Supply Chain Security Summit

"In the attacks observed, the threat actor used these vulnerabilities to access on-premises Exchange servers which enabled access to email accounts, and allowed installation of additional malware to facilitate long-term access to victim environments," Microsoft said.

(Excerpt) Read more at securityweek.com ...


TOPICS: Business/Economy; Crime/Corruption; Extended News; Foreign Affairs
KEYWORDS: chinesehacking; exchangeserver; microsoft; windowspinglist

1 posted on 03/02/2021 3:47:35 PM PST by bitt
[ Post Reply | Private Reply | View Replies]

To: ShadowAce; dayglored; Whenifhow; null and void; aragorn; EnigmaticAnomaly; kalee; Kale; ...

P


2 posted on 03/02/2021 3:47:59 PM PST by bitt (new q thread)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt

Stupid Microsoft. Don’t they know you can’t blame the ChiComs for anything anymore? That door closed on January 20, 2021.


3 posted on 03/02/2021 3:52:13 PM PST by Leaning Right (I have already previewed or do not wish to preview this composition )
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt
HAFNIUM primarily targets entities in the U.S. across a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.

QUARTERNIUM targets the financial sector, utilities, and Hollywood.

EIGHTHNIUM targets transportation, large industrial firms, and the petroleum industry.

TENTHNIUM targets every other firm in the USA.

4 posted on 03/02/2021 3:53:15 PM PST by ProtectOurFreedom (The Weak Never Started, The Cowards fail along the way, Only the Strong Survive)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
MS Exchange Mail Hack ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to bitt for the ping!

5 posted on 03/02/2021 3:53:46 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: bitt

Where in Heck is the Vaccine for this Chinese problem!!!!!

Hey Bill!!!!

Solve something real.

Oh, if you want to. Maybe you like China.


6 posted on 03/02/2021 3:55:04 PM PST by Scrambler Bob (This is not /s. It is just as viable as any MSM 'information', maybe more so!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt
Microsoft. When you absolutely, positively do not give a s**t Dorkbama about your data. Microsoft. Giving you unlimited viruses since the early 80s.
7 posted on 03/02/2021 3:57:39 PM PST by Da Coyote
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt
Four zero days???

You have to wonder how many zero days the Chinese have in their arsenal.

8 posted on 03/02/2021 3:58:31 PM PST by TChad (The MSM, having nuked its own credibility, is now bombing the rubble.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Leaning Right
Re: you can't blame the ChiComs anymore

Apparently, that policy is not polling well.

CNBC had a pro-Biden business article up this morning claiming that Biden is aggressively standing up to and blocking unfair Chinese trade practices.

9 posted on 03/02/2021 4:03:42 PM PST by zeestephen
[ Post Reply | Private Reply | To 3 | View Replies]

To: zeestephen

Practically ALL electronics and too much of everything else is made in China.
Of course the Communists never thought of copying every chip and program with the intent of adding backdoors!!!!¡


10 posted on 03/02/2021 4:30:02 PM PST by hoosierham (Freedom isn't free)
[ Post Reply | Private Reply | To 9 | View Replies]

To: bitt
“and allowed installation of additional malware to facilitate long-term access to victim environments," Microsoft said.”

So they don’t know how many bugs have been left on all those networks.

11 posted on 03/02/2021 4:45:25 PM PST by circlecity
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored

“Because it comes from Chy-Na!”


12 posted on 03/02/2021 5:12:48 PM PST by rockrr ( Everything is different now...)
[ Post Reply | Private Reply | To 5 | View Replies]

To: bitt

If we know HAFNIUM operates remotely thru US leased servers, where’s the FBI already?


13 posted on 03/02/2021 5:13:34 PM PST by mikey_hates_everything
[ Post Reply | Private Reply | To 1 | View Replies]

To: TChad

I read that stuxnet had something like three or four zero day exploits in it. This is how the big boys play.


14 posted on 03/02/2021 5:21:21 PM PST by coloradan (They're not the mainstream media, they're the gaslight media. It's what they do. )
[ Post Reply | Private Reply | To 8 | View Replies]

To: hoosierham
Of course the Communists never thought of copying every chip and program with the intent of adding backdoors!!!!

And it never occurred to the free traitors that the communists would do that.

15 posted on 03/02/2021 5:41:26 PM PST by TwelveOfTwenty (Still praying for our country and President Trump)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Da Coyote

Many companies use a suicide-pact combo of W10 PCs, MS Office 365, MS OneDrive (cloud) and MS Teams. Their MS-certified IT minions push them into it.

Unbelievably stupid to put all your company’s data in one basket, to me.

IT — They used to be called File Clerks, that pushed file carts, dropped and picked up folders and kept the file cabinet room secure.

Now, IT people think businesses exist to employ them richly, and that THEY direct the business. Next to them are HR people.

And then, there’s coders, who think we love to do things their way, love to fix what isn’t broken over and over and over, love censorship, and think we just can’t live without their apps.

/-rant


16 posted on 03/02/2021 5:54:29 PM PST by polymuser (A socialist is a communist without the power to take everything from their citizens...yet.)
[ Post Reply | Private Reply | To 7 | View Replies]

To: bitt

Why is microsoft allowing the attack?
They and isp’s around the country could block the ip address’s like “big tech” blocked Parlor and various people they do not like.


17 posted on 03/02/2021 6:53:30 PM PST by minnesota_bound (I need more money. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: Da Coyote

Funny. At every Black Hat conference I’ve attended, Linux was the first OS to go down. But you know, it’s stylish to shit on Microsoft. $1B+ annual commit to security and consistently top-right quadrant in Gartner for security, but yeah, Microsoft’s just doling out viruses like it’s Christmas.


18 posted on 03/03/2021 5:23:24 AM PST by rarestia (Repeal the 17th Amendment and ratify Article the First to give the power back to the people!)
[ Post Reply | Private Reply | To 7 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson