29 C
Delhi

Flaws in Microsoft’s Email Software raise alarms at the White House, DHS

The highest levels of the U.S. government are concerned and alarmed due to the newly discovered flaws in Microsoft Corp.’s software for email, which sees the government urging users to apply patches immediately.

Significant numbers of small businesses and local governments are among the 30,000 affected organizations across the U.S. They have been hacked via holes in Microsoft’s email software in the last few days allegedly by Chinese attackers who are focused on stealing email from victims, the blog KrebsonSecurity reported Friday.

“This is a significant vulnerability that could have far-reaching impacts,” said Jen Psaki, the White House press secretary, speaking at a briefing, according to Bloomberg. “We are concerned there are a large number of victims.” She characterized the incident as an “active threat.”

Psaki’s remark comes after Microsoft’s revelation on Tuesday that China-based nation-state hackers were exploiting flaws in on-premise versions of the software, which were previously unknown, and released patches for them. The following day, the Cybersecurity and Infrastructure Security Agency (CISA), which is part of the Department of Homeland Security, issued an emergency directive in response to “observed active exploitation of these products.” As a result of this, civilian agencies and departments were directed to apply the patches or look for compromises and disconnect Microsoft Exchange from their networks.

- Advertisement -TechnoSports-Ad

Over the course of this week, Government concern over the flaws continued to build, with CISA releasing an alert on Thursday, stating that it was aware of hackers using tools to search for servers that hadn’t yet been patched. That evening, National Security Advisor Jake Sullivan wrote on Twitter that the U.S. is “closely tracking Microsoft’s emergency patch.” He cited “reports of potential compromises of U.S. think tanks and defense industrial base entities.”

No specified target or timing of the hacking remains known. Defense Department spokesman John Kirby said the Pentagon (a metonym for the Department of Defense and its leadership) assesses its systems based on Microsoft’s advisory. The cybersecurity firm FireEye Inc. found that victims included “U.S.-based retailers, local governments, a university, and an engineering firm.” According to Allan Liska, an analyst at the firm Recorded Future Inc, the version of exchange targeted by hackers has been found out to be typically run by small businesses, putting them at special risk.

A Microsoft representative said the company isn’t aware of attacks before vulnerabilities were disclosed to the company in early January.

- Advertisement -TechnoSports-Ad

Volexity, a cybersecurity firm, reported finding attacks leveraging the flaws that date back to as early as 6th January. However, CISA urged operators to look for compromises dating back to September, “out of an abundance of caution,” according to a spokesperson.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.

TechnoSports-Ad

Popular

TechnoSports-Ad

Related Stories

More from author

Top 10 Richest Football Club Owners in the World in 2024

Football, one of the most popular sports with an estimated 4 billion fans worldwide, is not just a sport anymore but has also turned...

Top 5 players with the most goals for Indian national football team

Football is still a sport that is on the rise in India, with it still finding its feet among the public, though in recent...

Top 10 Most Popular Sports in the World in 2024

Here we bring to you the Top 10 Most popular sports in the world From our early childhood years when we take sports very seriously...

Top 10 Semiconductor Foundries of The World in 2023

Know the Top 10 Semiconductor Foundries in the world here as of 2023 A semiconductor foundry, also known as a fab or se­miconductor fabrication plant,...