Techno Vigilante

Techno Vigilante

Ataque masivo a servidores de Microsoft Exchange

Brian Krebs escribiendo en su blog Krebs on Security:

At least 30,000 organizations across the United States — including a significant number of small businesses, towns, cities and local governments — have over the past few days been hacked by an unusually aggressive Chinese cyber espionage unit that’s focused on stealing email from victim organizations, multiple sources tell KrebsOnSecurity. The espionage group is exploiting four newly-discovered flaws in Microsoft Exchange Server email software, and has seeded hundreds of thousands of victim organizations worldwide with tools that give the attackers total, remote control over affected systems.

On March 2, Microsoft released emergency security updates to plug four security holes in Exchange Server versions 2013 through 2019 that hackers were actively using to siphon email communications from Internet-facing systems running Exchange.

Microsoft said the Exchange flaws are being targeted by a previously unidentified Chinese hacking crew it dubbed “Hafnium,” and said the group had been conducting targeted attacks on email systems used by a range of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.

Impresionante la magnitud de este ataque. No debe ser menor que el historial del principal medio de comunicación de 30,000 empresas estadounidenses esté, al menos, en manos de un grupo proveniente de China. Además de lograr que se cuestione más a Microsoft en torno a la seguridad que ofrecen—gracias a que el ataque de SolarWinds y este afectaron solo infraestructura corriendo con tecnología de Microsoft—esto seguramente es algo que ya se tornó político.