Microsoft said the recent wave of Exchange breaches are not connected to the last year’s SolarWinds attacks. AP
Microsoft said the recent wave of Exchange breaches are not connected to the last year’s SolarWinds attacks. AP
Microsoft said the recent wave of Exchange breaches are not connected to the last year’s SolarWinds attacks. AP
Microsoft said the recent wave of Exchange breaches are not connected to the last year’s SolarWinds attacks. AP

More than 30,000 entities compromised through Microsoft’s Exchange flaws


Alkesh Sharma
  • English
  • Arabic

Cyber-espionage group Hafnium has exploited Microsoft’s widely used email and calendar Exchange server, breaching more than 30,000 commercial and local government entities in the US.

Criminals took advantage of disclosed flaws in the Exchange platform, a report by KrebsOnSecurity said.

They also tried to remotely take control of email servers of hundreds of thousands of other organisations globally, it said.

Microsoft disclosed four vulnerabilities in its Exchange server in a blog last week.

The gaps let hackers have access to email accounts and install malicious codes on their servers.

The company accused Hafnium, which operates from China, of plotting attacks against Exchange users.

Microsoft issued emergency patches and called on customers to install them.

The company has said the attacks are limited only to business customers and do not affect individual users.

Lotem Finkelsteen, director of threat intelligence at American-Israeli software company Check Point, said the Microsoft attack “is relevant to all businesses using Outlook but not to individual consumers … it is a server issue that the cyber attackers exploited".

Tom Burt, Microsoft’s corporate vice president of customer security and trust, said Exchange was mainly used by business customers.

Mr Burt said there was "no evidence that Hafnium’s activities targeted individual consumers or that these exploits impact other Microsoft products".

Hafnium is a “highly skilled” and “sophisticated" group that steals information from various sectors, including medical researchers, law firms, education institutions, defence, think tanks and NGOs, Microsoft said.

“While Hafnium is based in China, it conducts its operations primarily from leased virtual private servers in the US,” it said.

Microsoft's UAE office referred The National to its blog and declined to comment further.

The US government is assessing the effect, a White House official said on Saturday.

"This is an active threat, still developing, and we urge network operators to take it very seriously," the official said.

China's Foreign Ministry said it “firmly opposes and combats cyber attacks and cyber theft in all forms”.

It said that accusing a particular nation is a “highly sensitive political issue”.

Vulnerabilities found in Exchange servers were “significant” and “could have far-reaching impacts”, said Jen Psaki, the White House press secretary.

“We are concerned that there are a large number of victims,” Ms Psaki said.

cyber
cyber

The increase in cyber threats has led to a surge in spending on cyber security, which is forecast to rise about 125 per cent to $363.05 billion by 2025 from 2019, research consultancy Mordor Intelligence said.

Industry experts said Exchange exploits were not limited to the US and could affect entities in other parts of the world.

The flaws are "quite severe even if we don't know the full scope of those attacks", Satnam Narang, staff research engineer at cyber-security company Tenable in Maryland, told The National.

“While Microsoft says that Hafnium primarily targets entities within the US, other researchers say they've seen these vulnerabilities being exploited by different threat actors targeting other regions,” Mr Narang said.

Cyber-security company FireEye has identified affected victims in the US including retailers, local governments, a university and an engineering company.

A South-East Asian government and a central Asian telecoms company were also hit.

“In addition to patching as soon as possible, we recommend organisations review their systems for evidence of exploitation that may have occurred prior to the deployment of the patches,” said Charles Carmakal, senior vice president and chief technology officer of FireEye.

Microsoft has said the recent wave of breaches are "in no way connected" to last year's SolarWinds attacks by Russian hackers, which compromised nine US federal agencies and almost 100 businesses.

"State-sponsored hacking groups are exploiting critical Exchange bugs that Microsoft has already patched last week," Avinash Advani, founder and chief executive of Dubai cyber-security company CyberKnight, told The National.

"The disclosure will attract other threat actors looking to compromise unpatched servers.”

Company%20profile
%3Cp%3E%3Cstrong%3ECompany%20name%3A%3C%2Fstrong%3E%20Ogram%3Cbr%3E%3Cstrong%3EStarted%3A%20%3C%2Fstrong%3E2017%3Cbr%3E%3Cstrong%3EFounders%3A%3C%2Fstrong%3E%20Karim%20Kouatly%20and%20Shafiq%20Khartabil%3Cbr%3E%3Cstrong%3EBased%3A%20%3C%2Fstrong%3EDubai%2C%20UAE%3Cbr%3E%3Cstrong%3EIndustry%3A%3C%2Fstrong%3E%20On-demand%20staffing%3Cbr%3E%3Cstrong%3ENumber%20of%20employees%3A%3C%2Fstrong%3E%2050%3Cbr%3E%3Cstrong%3EFunding%3A%20%3C%2Fstrong%3EMore%20than%20%244%20million%3Cbr%3E%3Cstrong%3EFunding%20round%3A%3C%2Fstrong%3E%20Series%20A%3Cbr%3E%3Cstrong%3EInvestors%3A%20%3C%2Fstrong%3EGlobal%20Ventures%2C%20Aditum%20and%20Oraseya%20Capital%3Cbr%3E%3C%2Fp%3E%0A
RESULTS
%3Cp%3E%0D5pm%3A%20Al%20Maha%20Stables%20%E2%80%93%20Maiden%20(PA)%20Dh80%2C000%20(Turf)%201%2C400m%0D%3Cbr%3EWinner%3A%20AF%20Alfahem%2C%20Tadhg%20O%E2%80%99Shea%20(jockey)%2C%20Ernst%20Oetrel%20(trainer)%0D%3Cbr%3E5.30pm%3A%20Al%20Anoud%20Stables%20%E2%80%93%20Handicap%20(PA)%20Dh80%2C000%20(T)%201%2C200m%0D%3Cbr%3EWinner%3A%20AF%20Musannef%2C%20Tadhg%20O%E2%80%99Shea%2C%20Ernst%20Oertel%0D%3Cbr%3E6pm%3A%20Wathba%20Stallions%20Cup%20%E2%80%93%20Handicap%20(PA)%20Dh70%2C000%20(T)%201%2C400m%0D%3Cbr%3EWinner%3A%20AF%20Rasam%2C%20Tadhg%20O%E2%80%99Shea%2C%20Ernst%20Oertel%0D%3Cbr%3E6.30pm%3A%20Arabian%20Triple%20Crown%20Round%202%20%E2%80%93%20Group%203%20(PA)%20Dh%20300%2C000%20(T)%202%2C200m%0D%3Cbr%3EWinner%3A%20Joe%20Star%2C%20Tadhg%20O%E2%80%99Shea%2C%20Helal%20Al%20Alawi%0D%3Cbr%3E7pm%3A%20Liwa%20Oasis%20%E2%80%93%20Group%202%20(PA)%20Dh300%2C000%20(T)%201%2C400m%0D%3Cbr%3EWinner%3A%20AF%20Alajaj%2C%20Tadhg%20O%E2%80%99Shea%2C%20Ernst%20Oertel%0D%3Cbr%3E7.30pm%3A%20Dames%20Stables%20%E2%80%93%20Handicap%20(TB)%20Dh80%2C000%20(T)%201%2C400m%0D%3Cbr%3EWinner%3A%20Silent%20Defense%2C%20Oscar%20Chavez%2C%20Rashed%20Bouresly%3C%2Fp%3E%0A
Who's who in Yemen conflict

Houthis: Iran-backed rebels who occupy Sanaa and run unrecognised government

Yemeni government: Exiled government in Aden led by eight-member Presidential Leadership Council

Southern Transitional Council: Faction in Yemeni government that seeks autonomy for the south

Habrish 'rebels': Tribal-backed forces feuding with STC over control of oil in government territory

RESULTS

1.45pm: Maiden Dh75,000 1,400m
Winner: Dirilis Ertugrul, Fabrice Veron (jockey), Ismail Mohammed (trainer)
2.15pm: Handicap Dh90,000 1,400m
Winner: Kidd Malibu, Sandro Paiva, Musabah Al Muhairi
2.45pm: Maiden Dh75,000 1,000m
Winner: Raakezz, Tadhg O’Shea, Nicholas Bachalard
3.15pm: Handicap Dh105,000 1,200m
Winner: Au Couer, Sean Kirrane, Satish Seemar
3.45pm: Maiden Dh75,000 1,600m
Winner: Rayig, Pat Dobbs, Doug Watson
4.15pm: Handicap Dh105,000 1,600m
Winner: Chiefdom, Royston Ffrench, Salem bin Ghadayer
4.45pm: Handicap Dh80,000 1,800m
Winner: King’s Shadow, Richard Mullen, Satish Seemar

WHAT IS A BLACK HOLE?

1. Black holes are objects whose gravity is so strong not even light can escape their pull

2. They can be created when massive stars collapse under their own weight

3. Large black holes can also be formed when smaller ones collide and merge

4. The biggest black holes lurk at the centre of many galaxies, including our own

5. Astronomers believe that when the universe was very young, black holes affected how galaxies formed

MATCH INFO

Day 1 at Mount Maunganui

England 241-4

Denly 74, Stokes 67 not out, De Grandhomme 2-28

New Zealand 

Yet to bat

Results
%3Cp%3E%0D%3Cstrong%3EElite%20men%3C%2Fstrong%3E%0D%3Cbr%3E1.%20Amare%20Hailemichael%20Samson%20(ERI)%202%3A07%3A10%0D%3Cbr%3E2.%20Leornard%20Barsoton%20(KEN)%202%3A09%3A37%0D%3Cbr%3E3.%20Ilham%20Ozbilan%20(TUR)%202%3A10%3A16%0D%3Cbr%3E4.%20Gideon%20Chepkonga%20(KEN)%202%3A11%3A17%0D%3Cbr%3E5.%20Isaac%20Timoi%20(KEN)%202%3A11%3A34%0D%3Cbr%3E%3Cstrong%3EElite%20women%3C%2Fstrong%3E%0D%3Cbr%3E1.%20Brigid%20Kosgei%20(KEN)%202%3A19%3A15%0D%3Cbr%3E2.%20Hawi%20Feysa%20Gejia%20(ETH)%202%3A24%3A03%0D%3Cbr%3E3.%20Sintayehu%20Dessi%20(ETH)%202%3A25%3A36%0D%3Cbr%3E4.%20Aurelia%20Kiptui%20(KEN)%202%3A28%3A59%0D%3Cbr%3E5.%20Emily%20Kipchumba%20(KEN)%202%3A29%3A52%3C%2Fp%3E%0A