Multiple cyber threats lurking compromised systems: Microsoft

Facing multiple hacking attempts on its business email servers worldwide, Microsoft has reiterated the warning that patching a system does not necessarily remove the access of the attacker.
Hafnium Attack

5c9072b98876cf6361ec0e06da14dde0 1 e1616908186145Facing multiple hacking attempts on its business email servers worldwide, Microsoft has reiterated the warning that patching a system does not necessarily remove the access of the attacker.

The key vulnerabilities in the Microsoft business email servers have left cyber security experts flummoxed as this free-for-all attack opportunity is now being exploited by vast numbers of criminal gangs, state-backed threat actors and opportunistic “script kiddies,” researchers at F-Secure said last week.

Although many on-premises Microsoft Exchange servers have been patched, New investigation has found that multiple threats are still lurking on already-compromised systems.

According to Microsoft 365 Defender Threat Intelligence Team, many of the compromised systems have not yet received a secondary action, “such as human-operated ransomware attacks or data exfiltration, indicating attackers could be establishing and keeping their access for potential later actions”.

“These actions might involve performing follow-on attacks via persistence on Exchange servers they have already compromised, or using credentials and data stolen during these attacks to compromise networks through other entry vectors,” the tech giant said in its latest update.

May be an image of text that says 'ACER GETS HIT BY A RANSOMWARE ATTACK; acer HACKERS DEMAND THE BIGGEST RANSOM IN HISTORY: USD$ 50 MILLION CT'


Taiwanese electronics and computer maker Acer has already been hit by a ransomware attack where the hackers are demanding $50 million, the largest known ransom to date.


According to Bleeping Computer, hackers have accessed Acer documents that include financial spreadsheets, bank balances and bank communications, compromising its network via a Microsoft Exchange server vulnerability.

Earlier reports have claimed that five different hacking groups (including China-backed hacking group called ‘Hafnium’) are exploiting vulnerabilities in the business email servers of Microsoft.

According to Microsoft, attackers who included the exploit in their toolkits, whether through modifying public proof of concept exploits or their own research, capitalized on their window of opportunity to gain access to as many systems as they could.

“Some attackers were advanced enough to remove other attackers from the systems and use multiple persistence points to maintain access to a network,” the company noted.

Microsoft said that it is important to note that with “some post-compromise techniques, attackers may gain highly privileged persistent access, but many of the impactful subsequent attacker activities can be mitigated by practicing the principle of least privilege and mitigating lateral movement”.

According to the F-Secure report, countries currently seeing the most detections (in descending order) are Italy, Germany, France, the UK, the US, Belgium, Kuwait, Sweden, the Netherlands and Taiwan.

Picture of Michael Duff

Michael Duff

Leave a Replay

Search

Our Latest News

FL Computer Tech is best choice for Managed-IT in Florida but what about the rest of the US? Choosing the right Managed Service Provider, aka MSP, is a daunting and critical responsibility and that’s why we created the  OutSourced MSP website.  OutSourced MSP is a Managed Service Provider directory website that helps businesses nationwide find reputable, Managed-IT services. Check it out!

Recent Posts

New Agents in Microsoft Purview

Too many alerts can make it harder to focus on real data risks. ⚠️ New Microsoft Purview agents help cut through noise, highlight priority incidents, and surface risks using natural language queries. Watch the video to see how faster insight and action improve data security workflows. 🤖 @Microsoft Security

Read More »

Microsoft Copilot: Your AI companion

Communicating benefits changes doesn’t have to be complicated. 💬 Try this in Copilot Chat: “Draft a memo to employees announcing a change in health insurance carrier choices.” Copilot Chat helps you create clear, thoughtful communications, fast. So, employees know what’s changing and what to do next: https://copilot.microsoft.com/

Read More »

AI use Cases for Business Leaders

How can you turn AI investments into tangible impact? Learn from the experiences of the organizations featured in the eBook, ‘AI Use Cases for Business Leaders: Realize Value with AI.” Sharing insights from peers using Microsoft AI solutions like Copilot to drive value, it highlights how generative AI can help achieve goals such as: ✔️ Boosting employee productivity ✔️ Streamlining operations ✔️ Accelerating innovation Download your complimentary copy for ideas on how generative AI can help you drive measurable impact. 💡 @Microsoft Copilot @Microsoft 365

Read More »

Follow Us

Video Archive

Sign up for our Newsletter

Looking for the latest in technology news? Do you like tips, tricks and shortcuts? Sign up today!

Looking for the Best Managed-IT Business Solutions?

Need immediate computer support? A certified technician is only a call and a click away.

Subscribe our newsletter to get our latest update & news

3501 Quadrangle Blvd
Suite #305
Orlando, FL 32817

1-(941) 564-5464

Open Hours:

Mon - Sat: 8 am - 5 pm,
Sunday: CLOSED
24/7 Emergency Services Available