A new cybersecurity breach at Microsoft affects more than 30,000 American companies using the MS Exchange mail server solution. Cybersecurity specialists are already pretending that the Chinese state is behind this attack. Thousands of businesses and cities have been attacked, supposedly by a group of Chinese state-backed hackers through a Microsoft email hack.
According to unknown government sources the hack has been committed by an unusually aggressive Chinese cyber hackers unit.
Microsoft informed that those hackers in the so-called "Hafnium" group were exploiting zero-day security holes in its MS Exchange messaging services to steal data from business users. This "highly qualified and sophisticated player", according to Microsoft, has already targeted companies in the United States in the past.
These hackers get full remote control over infected systems. But there is apparently no connection to the previous SolarWinds hack, as mentioned by Microsoft chief Tom Burt. Microsoft released updates to fix the flaws, and urged customers to apply them. Applying patches quickly is the best protection against this attack. According to Microsoft, Hafnium is based in China, but operates through virtual private servers leased in the United States.
Last year, China accused Washington of defamation over allegations that Chinese hackers were trying to steal Covid-19 scientific research. And in January, US intelligence agencies named Russia as the main suspect in the massive hacking against the company and software SolarWinds, contradicting former President Donald Trump, who accused China of being behind that cyber attack. Microsoft declared that the Hafnium attacks were not related to the previous cyber attacks on SolarWinds.
Leave a Reply: