In turn, Microsoft admitted being hacked because of the SolarWinds vulnerability
Last weekend, security experts discovered that a group of Russian hackers have attacked a series of large global agencies and businesses through a vulnerability in SolarWinds' automatic update mechanism.
Taking advantage of a backdoor called Solarigate (ordered by Microsoft) or Sunburst (installed by FireEye), hackers have installed malicious software on the infrastructure of about 18,000 SolarWinds customers. Currently, the organizations hacked include the US Treasury Department, the US Homeland Security, the US Department of Energy and many other large organizations and enterprises.
According to Reuters, Microsoft was also hacked by the hacker group above through the SolarWinds vulnerability. Not only that, but Microsoft's software is also modified to infect customers as well as users.
Microsoft confirmed that they had been hacked but denied that their systems were used to attack other victims.
"We have found out SolarWinds files that contain malicious code on our system and have isolated and deleted them. We did not find any evidence that hackers have hacked into services. The utility or our customer data. Our investigations found no indication that our systems were being used to attack others, "Microsoft said.
The list of organizations and businesses hacked with SolarWinds vulnerability is growing. SolarWinds has more than 300,000 customers globally, including many large organizations and businesses. Therefore, this incident is assessed as extremely serious.
Currently, SolarWinds has cooperated with Microsoft, FireEye and many other security and security organizations to try to fix the problem. A patch for the exploited SolarWinds software has also been released.
Microsoft recommends that users do not turn off the Windows Update service. Most likely Microsoft will soon roll out security updates to ensure customers and users are safe.
You should read it
- The UN acknowledges that cyberattacks are extremely sophisticated and cannot identify the culprit
- Axie Infinity hacked with just a PDF file, the culprit is a North Korean hacker
- Microsoft Exchange server hacked by LockFile ransomware
- 5 signs that your family's surveillance camera has been hacked
- Microsoft admits that hacker Lapsus$ stole the source code
- How do hackers attack your Facebok account and how to prevent this process?
- Signs show clearly that your system is being hacked
- Computers that are not connected to the internet can still be hacked
May be interested
- Microsoft urges Admin to patch PowerShell vulnerability on Windowsmicrosoft has just asked for it admins of organizations and businesses to immediately patch the vulnerability in powershell 7. the reason is that this vulnerability allows hackers to bypass windows defender application control (wdac) enforcement measures.
- 'Printer Catastrophe' Vulnerability Threatens All Versions of Windowsalthough microsoft releases patches for windows vulnerabilities on a monthly basis, there are still security issues that remain. recently, the us cybersecurity and infrastructure agency (cisa) reported a critical vulnerability in the windows print spooler system.
- WhatsApp encrypted messaging application is hacked with just a phone calla vulnerability in whatsapp messaging service is used by bad guys to install israeli tracking software on users' phones.
- Detects a vulnerability that threatens all Windows computers shipped from 2012 up to nowsecurity researchers have found a vulnerability in the microsoft windows platform binary table (wpbt). this vulnerability can be exploited by hackers to install rootkits on all windows computers shipped from 2012 to the present.
- Signs show clearly that your system is being hackedif an email requests any sensitive information such as your address, bank account, social security number, or even the date of birth, chances are it's a fake email.
- Microsoft admits a new zero-day vulnerability threatens millions of Windows usersaccording to microsoft, this new zero-day vulnerability affects all versions of windows from windows 7 to windows 10 and corresponding versions of windows server.
- Microsoft warns of RCE vulnerability in Windows diagnostic toolif you've ever contacted microsoft support to get windows or windows server issues resolved, you've probably been guided through the microsoft support diagnostic tool (msdt). ).
- A series of famous accounts were hacked, TikTok issued an urgent announcementhackers took advantage of an undisclosed security vulnerability on the short video platform tiktok to attack the accounts of celebrities and big brands such as cnn, sony and paris hilton.
- Microsoft fixes a serious vulnerability that has existed for 17 years in Windows Serverthe vulnerability has tracking code cve-2020-1350 and its official name is sigred. it has been in windows dns server for nearly two decades and has only recently been successfully handled by the efforts of microsoft experts with help from the checkpoint security security team.
- Microsoft advises how to limit Excel vulnerabilitiescontrary to the predictions of security, microsoft has not released an emergency patch for the vulnerability - which is considered extremely serious. however, the software giant asserted 'actively building an update'.