Monday, March 08, 2021

US Reels From SolarWinds, Microsoft Exchange Attack One-Two Punch

Microsoft on Monday night issued patches for older, unsupported versions of its Exchange Server email software in the wake of a major hack linked to China. Microsoft on Monday night issued patches for older, unsupported versions of its Exchange Server email software in the wake of a major hack linked to China. The cyberattack, first reported by security researcher Brian Krebs on March 5, allowed hackers to access the email accounts of at least 30,000 organizations in the U.S. and 250,000 globally. A few days earlier Microsoft patched four zero-day exploits that hackers were using to attack on-premises versions of its popular email software program and attributed the exploits to a “highly skilled and sophisticated” China-based group called Hafnium. “Historically, Hafnium primarily targets entities in the United States for the purpose of exfiltrating information from a number of industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks and NGOs,” Microsoft’s Tom Burt, corporate VP for customer security and trust, wrote in a blog post. However, in the days following the Exchange Server security updates, the same Chinese hacking group “dramatically stepped up attacks” on unpatched systems, Krebs reported. And this promoted Microsoft to issue additional security updates today for older, unsupported versions of Exchange Server. “The availability of these updates does not mean that you don’t have to keep your environment current,” Microsoft warned in a blog post. “This is intended only as a temporary measure to help you protect vulnerable machines right now.” Meanwhile, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), in a tweet, urged “ALL organizations across ALL sectors” to update their Microsoft Exchange Server email software and address the vulnerabilities. CISA also issued guidelines for executives and IT security staff on how to fix the flaws. And the Biden administration is expected to form a task force to deal with the Microsoft hack. A White House official called it an “active threat” and urged “network operators to take it very seriously.” The attack on Microsoft Exchange comes as corporations and federal agencies in the United States are still reeling from the earlier SolarWinds breach by Russian state-sponsored hackers. “The Chinese attackers know exactly what they are doing,” Cybereason CEO Lior Div said. “The new administration has been distracted by investigations into another U.S. adversary on the cyber battlefield — Russia — and its calculated breach against SolarWinds.” And while SolarWinds had “crippling effects” on hundreds of U.S. businesses and at least nine government agencies, “the newest assault against Microsoft Exchange is 1,000 times more devastating because the Chinese attackers have targeted SMEs,” he continued, adding that small and midsized enterprises are “the lifeblood of the U.S. economy and the driver of the global economy.” Additionally, they experienced a harder economic hit from the COVID-19 pandemic compared to their larger counterparts. “And just when we are starting to turn the corner after a devastating year, this attack against SMEs is launched,” Div said. “This attack is potentially even more damaging because SMEs typically don’t typically have as robust a security posture in place, allowing threat actors to prey on the weak and drive strong revenue streams this way.” The federal government also use Microsoft Exchange Server, and while it’s still unclear if any federal agencies were breached in the attack, CISA issued an emergency directive requiring agencies to immediately patch the software and, if they find any indication of an attack, disconnect the email program. New research indicates that the Russians weren’t the only state-sponsored hackers to exploit SolarWinds software. Secureworks Counter Threat Unit researchers on Monday said Spiral, a hacking group with ties to China, also exploited the authentication bypass vulnerability in SolarWinds Orion API. “The abuse of vulnerabilities in both intrusions reinforces the importance of applying security updates as soon as possible,” the threat researchers wrote in a blog post. “However, network breaches can occur even with preventative measures in place. Organizations should consider implementing an EDR solution for real-time network monitoring and alerting. CTU researchers also advise organizations to prepare and test a robust incident response plan.”

Archive