Move over, SolarWinds: 30,000 orgs’ email hacked via Microsoft Exchange Server flaws

Move over, SolarWinds: 30,000 orgs’ email hacked via Microsoft Exchange Server flaws

Four exploits found in Microsoft’s Exchange Server software have reportedly led to over 30,000 US governmental and commercial organizations having their emails hacked, according to a report by KrebsOnSecurity. Wired is also reporting “tens of thousands of email servers” hacked. The exploits have been patched by Microsoft, but security experts talking to Krebs say that…

Chinese Hackers Breach Microsoft Business Email Software Raising Security Crisis Globally. Details Here

Chinese Hackers Breach Microsoft Business Email Software Raising Security Crisis Globally. Details Here

San Francisco: In a big cyber attack, China-based threat actors hacked at least 30,000 organisations across the US, including government and commercial firms, by using Microsoft’s Exchange Server software to enter their networks. The espionage group is known to have exploited four vulnerabilities in Microsoft Exchange Server email software, which provided them access to email…

Qualys admits its Accellion FTA server compromised by attacker

Qualys admits its Accellion FTA server compromised by attacker

Qualys, which provides a cloud-based platform for protecting IT and OT workloads, has become the latest firm to be victimized by vulnerabilities in the Accellion FTA file transfer application. Company CISO Ben Carr said Wednesday it had deployed an Accellion FTA server in a segregated DMZ environment, completely separate from systems that host and support…

Hackers breached four prominent underground cybercrime forumsSecurity Affairs

Hackers breached four prominent underground cybercrime forumsSecurity Affairs

A suspicious wave of attacks resulted in the hack of four cybercrime forums Verified, Crdclub, Exploit, and Maza since January. Since January, a series of mysterious cyberattacks that resulted in the hack of popular Russian-language cybercrime forums. Unknown threat actors hacked the Verified forum in January, Crdclub in February, and Exploit and Maza in March,…

Microsoft says Chinese hackers targeted groups via server software

Microsoft says Chinese hackers targeted groups via server software

By Raphael Satter, Christopher Bing WASHINGTON (Reuters) – A China-linked cyber-espionage group has been remotely plundering email inboxes using freshly discovered flaws in Microsoft mail server software, the company and outside researchers said on Tuesday – an example of how commonly used programs can be exploited to cast a wide net online. In a blog…

Hackers breached four prominent underground cybercrime forumsSecurity Affairs

Hackers breached four prominent underground cybercrime forumsSecurity Affairs

A suspicious wave of attacks resulted in the hack of four cybercrime forums Verified, Crdclub, Exploit, and Maza since January. Since January, a series of mysterious cyberattacks that resulted in the hack of popular Russian-language cybercrime forums. Unknown threat actors hacked the Verified forum in January, Crdclub in February, and Exploit and Maza in March,…

NSA, CISA, issue guidance on Protective DNS services

NSA, CISA, issue guidance on Protective DNS services

The National Security Agency (NSA) and Cybersecurity and Infrastructure Agency (CISA) released a joint information sheet Thursday that offers guidance on the benefits of using a Protective Domain Name System (PDNS). A PDNS service uses existing DNS protocols and architecture to analyze DNS queries and mitigate threats. It leverages various open source, commercial, and governmental…

At least 30,000 US organizations victims of Microsoft Exchange hack: Krebs

At least 30,000 US organizations victims of Microsoft Exchange hack: Krebs

At least 30,0000 organizations across the US have been hacked over the last few days through flaws in Microsoft’s Exchange server email software, sources familiar with the matter told KrebsOnSecurity. The “unusually aggressive Chinese cyber espionage unit” that Microsoft calls “Hafnium” is focusing on stealing emails from a range of victims, including companies, small businesses,…

Qualys Gets ‘Clopped’ by Accellion-Exploiting Attackers

Qualys Gets ‘Clopped’ by Accellion-Exploiting Attackers

Breach Notification , Cybercrime , Fraud Management & Cybercrime Security Firm Confirms Breach After Clop Ransomware Gang Posts Stolen Customer Data Mathew J. Schwartz (euroinfosec) • March 4, 2021     Leaked Qualys customer information (Source: Clop leaks site) Cybersecurity firm Qualys has confirmed that its systems were breached by attackers who hacked its Accellion…