Microsoft, Security Patch and Chinese Hackers
Digest more
Microsoft has warned that Chinese state-sponsored hackers have breached its SharePoint software used by the US agency responsible for maintaining and modernizing the nation’s stockpile of nuclear weapons, according to a report.
Hackers sponsored by the Chinese state have breached a number of U.S. government institutions, including the agency responsible for overseeing the security of America’s nuclear arsenal, Microsoft warned.
New estimates regarding the recently-exploited Microsoft SharePoint vulnerabilities now evaluate that as many as 400 organizations may have been targeted.
A China-linked threat actor has been observed exploiting SharePoint servers to deliver ransomware, according to Microsoft researchers, in the latest sign of worsening attacks against on-premises SharePoint Server customers.
A July 8 fix for a critical SharePoint zero-day failed to stop active exploitation, enabling state-backed attackers to breach nearly 100 organizations worldwide.
The move comes after a ProPublica report highlighted a Microsoft program that allows foreign engineers to indirectly interact with U.S. military systems through American “escort” intermediaries.
Chinese workers are accompanied by US citizens functioning as 'digital escorts,' but the practice functions 'with little review,' according to a ProPublica investigation.
After a ProPublica investigation raised security concerns, Microsoft will cease using China-based engineers for work on sensitive Pentagon cloud computing systems.
2d
DPA International on MSNChina warns against defamation over Microsoft security breachThe Chinese government has warned against using cyber security issues to defame the country, following the hacker attacks on Microsoft software. Foreign Ministry spokesman Guo Jiakun said in Beijing on Wednesday that he was not aware of the exact circumstances of the attacks.
A series of cyberattacks targeting Microsoft collaboration software, specifically SharePoint, have been linked to Chinese hackers and threat actors.