logo
China-backed hackers used Microsoft flaw in attacks, defenders say

China-backed hackers used Microsoft flaw in attacks, defenders say

Washington Post4 days ago
Hackers connected to the Chinese government were behind at least some of the widespread attacks in the past few days on organizations that use collaboration software from Microsoft, defenders working on the intrusions said in interviews.
The breaches in the United States and other countries took advantage of a disastrous security flaw that drew attention this month, after Microsoft issued a patch that fixed only part of the problem in SharePoint, which is widely used to coordinate work on documents and projects.
'We assess that at least one of the actors responsible for this early exploitation is a China-nexus threat actor,' said Charles Carmakal, chief technology officer of Google's Mandiant Consulting.
Another researcher, who, like others, spoke on the condition of anonymity because the inquiry is still underway, said federal investigators have evidence of U.S.-based servers linked to compromised SharePoint systems connecting to internet Protocol addresses inside China on Friday and Saturday.
The FBI, White House, and the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency declined to comment Monday.
Two other responders working with the U.S. government said they had identified early attacks from China as well. The Chinese Embassy in Washington did not immediately respond to a request for comment.
The attacks allowed hackers to extract cryptographic keys from servers run by Microsoft clients. Those keys, in turn, would let them install anything, including back doors that they could use to return. Federal and state agencies were affected, researchers previously told The Washington Post, but it remains unclear which of them were vulnerable to follow-up attacks.
Only versions of SharePoint that are hosted by the customer, not those in the cloud, are vulnerable. Microsoft issued effective patches for the last of the exposed versions by Monday.
While installing the patches should prevent new intrusions, customers also need to change the machine's digital keys, apply anti-malware software and hunt for any breaches that have already occurred, Microsoft said.
Some of the early targets of the attack were entities that would interest the Chinese government, two of the responders said. But a wide range of attackers were now trying similar grabs, others said, looking to steal corporate secrets or install ransomware that encrypts key files until payments are made.
'It's critical to understand that multiple actors are now actively exploiting this vulnerability. We fully anticipate that this trend will continue, as various other threat actors, driven by diverse motivations, will leverage this exploit as well,' Carmakal said.
Piet Kerkhofs, CTO and co-founder of Europe-based Eye Security, said the SharePoint breaches share characteristics with other compromises that security researchers have attributed to China-based hackers.
For instance, hackers this month exploited a vulnerability in Citrix's NetScaler virtual desktop that some researchers saw being used by Chinese actors, Kerkhofs said. That hack was similar to the SharePoint compromise in that it turned a freshly discovered vulnerability into an 'exploit' or weapon — in 'extremely fast' order, 'hours to days,'' he said.
Another instance was China's global compromise of Microsoft Exchange email servers in early 2021. That case involved Chinese government-sponsored hackers conducting widespread exploitation of core Microsoft software — its Exchange email server software.
That breach has been attributed to group that Microsoft calls Silk Typhoon, which is linked to China's Ministry of State Security. It is one of the most technically advanced hacking groups in the world and has been striking sensitive U.S. targets at an increased rate in the past year, The Post reported last week.
Silk Typhoon has broken into multiple U.S. federal agencies in the past and more recently hit multiple ministries in Europe, The Post reported.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Jensen Huang Says He's Created More Billionaires Than Any CEO: 'Don't Feel Sad For Anybody At My Layer'
Jensen Huang Says He's Created More Billionaires Than Any CEO: 'Don't Feel Sad For Anybody At My Layer'

Yahoo

time12 minutes ago

  • Yahoo

Jensen Huang Says He's Created More Billionaires Than Any CEO: 'Don't Feel Sad For Anybody At My Layer'

Benzinga and Yahoo Finance LLC may earn commission or revenue on some items through the links below. As the Donald Trump administration unveiled its AI policy plan, Nvidia Corp. (NASDAQ:NVDA) CEO Jensen Huang joined top Silicon Valley figures to weigh in on the cutthroat battle for AI talent and compensation during a live podcast in Washington, D.C. What Happened: Earlier this week, appearing on the All-in podcast alongside venture capitalists Chamath Palihapitiya and Jason Calacanis, Huang pushed back on concerns about executive-level compensation amid billion-dollar offers for AI researchers. During the conversation, Palihapitiya raised the point that AI researchers were being offered unprecedented contracts—one reportedly as high as $1 billion over four years from Meta Platforms Inc. (NASDAQ:META). He asked why similar valuations weren't seen at the CEO level, despite their role in enabling breakthroughs. "First of all, I've created more billionaires on my management team than any CEO in the world. They're doing just fine," Huang said. "Don't feel sad for anybody at my layer." Trending: 7,000+ investors have joined Timeplast's mission to eliminate microplastics— Huang also underscored the efficiency of small, well-funded teams in AI. "The impact of 150 or so AI researchers can probably create, with enough funding, an OpenAI. There's something about the elegance of small teams," he said. Later, Calacanis added levity, teasing Huang about rumors of a secret stash of stock options. "Somebody told me you just drop RSUs on people if they do a great job," he joked. "That's nuts," Huang responded, adding, "I review everyone's comp myself ... and I 100% of the time increase opex because you take care of people and everything else takes care of itself." Why It's Important: The discussion came during the Trump administration's unveiling of its AI Action Plan, a strategic initiative backed by a new wave of Silicon Valley. The fierce competition for AI talent has driven record compensation and high-profile hires across companies like Meta, Microsoft Corp. (NASDAQ:MSFT), OpenAI and Alphabet Inc.'s (NASDAQ:GOOG) (NASDAQ:GOOGL) Google DeepMind—often eclipsing executive salaries and reshaping the power dynamics in the tech world. Earlier this week, Alphabet CEO Sundar Pichai also dismissed concerns over an AI talent exodus, stating the company remains strong in attracting and retaining top AI experts. Read Next: $100k+ in investable assets? Match with a fiduciary advisor for free to learn how you can maximize your retirement and save on taxes – no cost, no obligation. Warren Buffett once said, "If you don't find a way to make money while you sleep, you will work until you die." Here's how you can earn passive income with just $100. Photo courtesy: jamesonwu1972 On This article Jensen Huang Says He's Created More Billionaires Than Any CEO: 'Don't Feel Sad For Anybody At My Layer' originally appeared on Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

With Columbia as a model, White House seeks fines in potential deals with Harvard and others
With Columbia as a model, White House seeks fines in potential deals with Harvard and others

Associated Press

time14 minutes ago

  • Associated Press

With Columbia as a model, White House seeks fines in potential deals with Harvard and others

WASHINGTON (AP) — The White House is pursuing heavy fines from Harvard and other universities as part of potential settlements to end investigations into campus antisemitism, using the deal it struck with Columbia University as a template, according to an administration official familiar with the matter. Fines have become a staple of proposed deals in talks with Harvard and other schools, according to the official, who spoke on the condition of anonymity to discuss internal deliberations. The new strategy was first reported by The Wall Street Journal. Federal civil rights investigations into schools and universities almost always have been resolved through voluntary settlements, yet they rarely include financial penalties. The Biden administration reached dozens of such deals with universities and none included fines. Columbia's settlement with the Trump administration included a $200 million fine in exchange for regaining access to federal funding and closing investigations accusing Columbia of tolerating harassment of Jewish students and employees. The agreement announced Wednesday also orders Columbia to ensure its admissions and hiring decisions are 'merit-based' with no consideration of race, to hire more Jewish studies faculty, and to reduce the university's reliance on international students, among other changes. It places Columbia under the watch of an independent monitor and requires regular disclosures to the government. The agreement deal includes a clause forbidding the government from directly dictating decisions on hiring, admissions or academics. Columbia leaders said it preserves the university's autonomy while restoring the flow of federal money. The Trump administration is investigating dozens of universities over allegations that they failed to address campus antisemitism amid the Israel-Hamas war, and several institutions have faced federal funding freezes, like those at Columbia and Harvard. The federal government has frozen more than $1 billion at Cornell University, along with $790 million at Northwestern University. In announcing the Columbia settlement, administration officials described it as a template for other universities. Education Secretary Linda McMahon called it a 'roadmap' for colleges looking to regain public trust, saying it would 'ripple across the higher education sector and change the course of campus culture for years to come.' As Trump departed the White House on Friday, he told reporters that Harvard 'wants to settle' but that Columbia 'handled it better.' The president said he's optimistic his administration will prevail in Harvard's legal challenge — at least on appeal — and he suggested Harvard may never regain the level of federal funding it received in the past. 'The bottom line is we're not going to give any more money to Harvard,' he said. 'We want to spread the wealth.' ___ The Associated Press' education coverage receives financial support from multiple private foundations. AP is solely responsible for all content. Find AP's standards for working with philanthropies, a list of supporters and funded coverage areas at

Beyond The Hype: What It Takes To Win In Cannabis This Year
Beyond The Hype: What It Takes To Win In Cannabis This Year

Forbes

time14 minutes ago

  • Forbes

Beyond The Hype: What It Takes To Win In Cannabis This Year

cannabis, marijuana in America has just slowly been legalized and used for medicinal and medical ... More purposes Despite continuing federal roadblocks, 2025 is still an exciting time to be a cannabis entrepreneur. Half of all U.S. states now allow recreational cannabis use and nearly all states allow medical cannabis use. But the industry is complicated, with each state rolling out different rules, regulations, and tax structures. Greg James, publisher of Marijuana Venture, a business magazine dedicated to the industry, and founder of the Interchange business to business cannabis trade show, has advice for those ready to dive in. 1. Examine how the market in your state is being created. Know how many licenses are being awarded. 'If your state awards 1200 grower's licenses to supply 450 licensed stores, for example, you'll inevitably have a big oversupply of cannabis,' said James. Testing, tracking and packaging rules vary from state to state and require a detail-oriented focus for compliance. Know the tax structures to help determine your profitability, and understand that due to federal law, you cannot write off business expenses like other industries can said James. A farmer holds a low-THC hemp plant .Thursday, Sept. 5, 2024. A Photographer: Valeria ... More Mongelli/Bloomberg 2. Visit growers or store owners in states like Washington, Oregon and Colorado that have had legal cannabis sales for years to see the realities of day-to-day operations and challenges owners face. 'Too many people just rush headlong into the business without talking to people who have been through it,' James said. The unanticipated problems and lessons learned in the early legal states, often crop up again in states that legalize cannabis later. 3. If you plan to grow cannabis, decide if you'll grow it indoors or outdoors said James. Indoor grows are more expensive to run, but offer better control when it comes to wind, water, light and pests. 'Indoor buds turn out prettier,' said James, 'so they command a premium price.' Outdoors, 'the sun is free,' he said, and other costs can be lower, but you are at the mercy of nature. Typically, outdoor grows produce a higher volume of cannabis, but the market for it will likely be wholesalers and processors who will pay a bit less and use it to process into oil for edibles said James. The strains and potency of the plants can be the same indoors or out. Cannabis strains (Photo by Bob Riha, Jr./Getty Images) 4. Hire professional, experienced staff. 'Hire a real CFO and accountant, know your cost of goods,' said James. Don't go into business with your friends because you think it will be an easy way to make money, he said. You will need agricultural, retail, financial, logistics or packaging experts – don't skimp here. 'They have these things called Ag Universities for a reason, and they're pretty good at turning out folks with degrees that are focused on how to make horticulture more productive and profitable,' he said. 5. Use the latest technology. That includes modern growing techniques like LED lighting and aeroponics. Climate control systems can monitor and regulate all the inputs in modern greenhouses and hoop houses. Decades of research and studies in agriculture have increased production across all crops in the U.S., said James, and cannabis can adopt those same technologies. farmer using tablet to monitor control cannabis plantation in greenhouse. 6. If you are selling cannabis products into stores or dispensaries, put your salespeople in front of buyers often. 'Once you've gotten your goods into a store, that's the beginning of your relationship, not the end,' James said. Your sales force has to follow up and see how the products are moving, maintain relationships, and brainstorm what other products the stores' customers might like. Just because they stock you once, does not meant they will automatically reorder forever, he said. James said he has seen growers and processors who were successful initially, but found themselves failing once their competitors spent more time refining their offerings with new ideas and price points. Cannabis is a constantly evolving business so keep evolving your offerings. Cannabis shop (Photo by Bob Riha, Jr./Getty Images) 7. Retailers, your store may be an exciting destination when it opens, said James, but as soon as a more convenient shop appears, "no one will drive out of their way, so choose a location with good foot traffic and lots of parking.' It may seem basic, but parking can make or break a store's success he said. Hire friendly, approachable budtenders who can make people feel comfortable, whether they are a frat bro or a soccer mom. And like any retail store, good lighting, attractive displays and a good selection of products that are easy to find are key.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store