Saturday, April 17, 2021
  • About
  • Advertise
  • Privacy & Policy
  • Contact
No Result
View All Result
Tech News, Magazine & Review WordPress Theme 2017
  • Tech

    The Best Smartphones You Can Buy Under Rs. 20,000

    The Best Smartphones You Can Buy Under Rs. 20,000

    The Best Smartphones You Can Buy Under Rs. 20,000

    The Best Smartphones You Can Buy Under Rs. 20,000

    DPIIT notifies PLI scheme for ACs, LED lights; mere assembly of finished goods not to be incentivised

    An emerging security paradigm for the post pandemic world

    Facebook Oversight Board Extends Timeline to Decide on Donald Trump Ban

    Facebook Oversight Board Extends Timeline to Decide on Donald Trump Ban

    Google Misled Consumers About Data Collection, Says Australian Watchdog

  • Apps
  • Computers
  • Camera
  • Mobile
  • Smart Devices

    Fitbit Luxe Could Launch Soon as Company’s Most Elegant Fitness Tracker Yet

    Is OnePlus 9R the Best Phone Under Rs. 40,000?

    Mi TV EA 2022 Range With Metal Unibody Design Launched

    Zebronics Zeb-Fit2220CH Fitness Band With 8 Sports Modes Launched in India

    Beosound Emerge by Bang & Olufsen With Unique Book-Like Design Launched

    Sony 32W830 Android TV With Google Assistant and HDR Launched in India

    TicWatch GTH Smartwatch With Up to 10 Days Battery Life Launched

    ACT HomeCam Security Camera Launched in India: All the Details

    Samsung Neo QLED TV Range Debuts in India With 8K and 4K Variants

  • Software
  • Audio

    Apple AirPods Max vs Sony WH-1000XM4

    AirPods 3 Image Surface Online, New Apple Pencil Tipped to Be in the Works

    Beosound Emerge by Bang & Olufsen With Unique Book-Like Design Launched

    Anker PowerConf C300 HD Webcam, S500 Portable Conference Speaker Launched

    Amazon Echo Buds (2nd Gen) Get ANC in a Smaller Design

    Spotify Car Thing In-Car Accessory Is Free for a Limited Time: See Details

    TCL Launches 3 True Wireless Earphones in India

    Apple TV With Integrated HomePod and Camera Said to Be in the Works

    Mi AI Smart Speaker (Second Generation) With 8W Output Launched

  • TV
  • Tech

    The Best Smartphones You Can Buy Under Rs. 20,000

    The Best Smartphones You Can Buy Under Rs. 20,000

    The Best Smartphones You Can Buy Under Rs. 20,000

    The Best Smartphones You Can Buy Under Rs. 20,000

    DPIIT notifies PLI scheme for ACs, LED lights; mere assembly of finished goods not to be incentivised

    An emerging security paradigm for the post pandemic world

    Facebook Oversight Board Extends Timeline to Decide on Donald Trump Ban

    Facebook Oversight Board Extends Timeline to Decide on Donald Trump Ban

    Google Misled Consumers About Data Collection, Says Australian Watchdog

  • Apps
  • Computers
  • Camera
  • Mobile
  • Smart Devices

    Fitbit Luxe Could Launch Soon as Company’s Most Elegant Fitness Tracker Yet

    Is OnePlus 9R the Best Phone Under Rs. 40,000?

    Mi TV EA 2022 Range With Metal Unibody Design Launched

    Zebronics Zeb-Fit2220CH Fitness Band With 8 Sports Modes Launched in India

    Beosound Emerge by Bang & Olufsen With Unique Book-Like Design Launched

    Sony 32W830 Android TV With Google Assistant and HDR Launched in India

    TicWatch GTH Smartwatch With Up to 10 Days Battery Life Launched

    ACT HomeCam Security Camera Launched in India: All the Details

    Samsung Neo QLED TV Range Debuts in India With 8K and 4K Variants

  • Software
  • Audio

    Apple AirPods Max vs Sony WH-1000XM4

    AirPods 3 Image Surface Online, New Apple Pencil Tipped to Be in the Works

    Beosound Emerge by Bang & Olufsen With Unique Book-Like Design Launched

    Anker PowerConf C300 HD Webcam, S500 Portable Conference Speaker Launched

    Amazon Echo Buds (2nd Gen) Get ANC in a Smaller Design

    Spotify Car Thing In-Car Accessory Is Free for a Limited Time: See Details

    TCL Launches 3 True Wireless Earphones in India

    Apple TV With Integrated HomePod and Camera Said to Be in the Works

    Mi AI Smart Speaker (Second Generation) With 8W Output Launched

  • TV
No Result
View All Result
Indian Technology News
No Result
View All Result
Home Tech

Russia has allegedly hit the US with an unprecedented malware attack: Here’s what you need to know

January 6, 2021
Share on FacebookShare on Twitter

US Intelligence agencies have said Russia is responsible for a major hacking campaign striking federal agencies and major tech companies


Angela Lang/CNET

US intelligence agencies attributed a sophisticated malware campaign to Russia in a joint statement Tuesday, several weeks after public reports of the hack that has affected local, state and federal agencies in the US in addition to private companies including Microsoft. The massive breach, which reportedly compromised an email system used by senior leadership at the Treasury Department and systems at several other federal agencies, started in March 2020 when hackers compromised IT management software from SolarWinds. 

The FBI and NSA joined the Cybersecurity and Infrastructure Security Agency and the Office of the Director of National Intelligence in saying the hack was “likely Russian in origin” on Tuesday but stopped short of naming a specific hacking group or Russian government agency as being responsible.

Stay in the know

Get the latest tech stories with CNET Daily News every weekday.

Austin, Texas-based SolarWinds sells software that lets an organization see what’s happening on its computer networks. Hackers inserted malicious code into an update of that software, which is called Orion. Around 18,000 SolarWinds customers installed the tainted update onto their systems, the company said. The compromised update has had a sweeping impact, the scale of which keeps growing as new information emerges.

The joint statement Tuesday called the hack “a serious compromise that will require a sustained and dedicated effort to remediate.”

On Dec. 19, President Donald Trump floated on Twitter the idea that China might be behind the attack. Trump, who didn’t provide evidence to support the suggestion of Chinese involvement, tagged Secretary of State Mike Pompeo, who had earlier said in a radio interview that “we can say pretty clearly that it was the Russians that engaged in this activity.”

In a joint statement, US national security agencies have called the breach “significant and ongoing.” It’s still unclear how many agencies are affected or what information hackers might have stolen so far. But by all accounts, the malware is extremely powerful. According to an analysis by Microsoft and security firm FireEye, both of which were infected, the malware gives hackers broad reach into impacted systems.

Microsoft said it had identified more than 40 customers that were targeted in the hack. More information is likely to emerge about the compromises and their aftermath. Here’s what you need to know about the hack:

How did hackers sneak malware into a software update?

Hackers managed to access a system that SolarWinds uses to put together updates to its Orion product, the company explained in a Dec. 14 filing with the SEC. From there, they inserted malicious code into otherwise legitimate software update. This is known as a supply-chain attack since it infects software as it’s under assembly.

It’s a big coup for hackers to pull off a supply-chain attack because it packages their malware inside a trusted piece of software. Instead of having to trick individual targets into downloading malicious software with a phishing campaign, the hackers could just rely on several government agencies and companies to install the Orion update at SolarWinds’ prompting. 

The approach is especially powerful in this case because thousands of companies and government agencies around the world reportedly use the Orion software. With the release of the tainted software update, SolarWinds’ vast customer list became potential hacking targets.

What do we know about Russian involvement in the hack?

US intelligence officials have publicly blamed the hack on Russia. A joint statement Jan. 5 from the FBI, NSA, CISA and the ODNI said the hack was most likely from Russia. Their statement followed remarks from Pompeo in a Dec. 18 interview in which he attributed the hack to Russia. Additionally, news outlets had cited government officials throughout the previous week who said a Russian hacking group is believed to be responsible for the malware campaign.

SolarWinds and cybersecurity firms have attributed the hack to “nation-state actors” but haven’t named a country directly.

In a Dec. 13 statement on Facebook, the Russian embassy in the US denied responsibility for the SolarWinds hacking campaign. “Malicious activities in the information space contradict the principles of the Russian foreign policy, national interests and our understanding of interstate relations,” the embassy said, adding, “Russia does not conduct offensive operations in the cyber domain.”

Nicknamed APT29 or CozyBear, the hacking group pointed to by news reports has previously been blamed for targeting email systems at the State Department and White House during the administration of President Barack Obama. It was also named by US intelligence agencies as one of the groups that infiltrated the email systems of the Democratic National Committee in 2015, but the leaking of those emails isn’t attributed to CozyBear. (Another Russian agency was blamed for that.)

More recently, the US, UK and Canada have identified the group as responsible for hacking efforts that tried to access information about COVID-19 vaccine research.

Which government agencies were infected with the malware?

According to reports from Reuters, The Washington Post and The Wall Street Journal, the malware affected the US departments of Homeland Security, State, Commerce and Treasury, as well as the National Institutes of Health. Politico reported on Dec. 17 that nuclear programs run by the US Department of Energy and the National Nuclear Security Administration were also targeted. 

Reuters reported on Dec. 23 that CISA has added local and state governments to the list of victims. According to CISA’s website, the agency is “tracking a significant cyber incident impacting enterprise networks across federal, state, and local governments, as well as critical infrastructure entities and other private sector organizations.”

It’s still unclear what information, if any, was stolen from government agencies, but the amount of access appears to be broad.

Though the Energy Department and the Commerce Department and Treasury Department have acknowledged the hacks, there’s no official confirmation that other specific federal agencies have been hacked. However, the Cybersecurity and Infrastructure Security Agency put out an advisory urging federal agencies to mitigate the malware, noting that it’s “currently being exploited by malicious actors.”

In a statement on Dec. 17, President-elect Joe Biden said his administration will “make dealing with this breach a top priority from the moment we take office.”

Why is the hack a big deal?

In addition to gaining access to several government systems, the hackers turned a run-of-the-mill software update into a weapon. That weapon was pointed at thousands of groups, not just the agencies and companies that the hackers focused on after they installed the tainted Orion update.

Microsoft President Brad Smith called this an “act of recklessness” in a wide-ranging blog post on Dec. 17 that explored the ramifications of the hack. He didn’t directly attribute the hack to Russia, but described its previous alleged hacking campaigns as proof of an increasingly fraught cyber conflict.

“This is not just an attack on specific targets,” Smith said, “but on the trust and reliability of the world’s critical infrastructure in order to advance one nation’s intelligence agency.” He went on to call for international agreements to limit the creation of hacking tools that undermine global cybersecurity.

Former Facebook cybersecurity chief Alex Stamos said Dec. 18 on Twitter that the hack could lead to supply-chain attacks becoming more common. However, he questioned whether the hack was anything out of the ordinary for a well-resourced intelligence agency.

“So far, all of the activity that has been publicly discussed has fallen into the boundaries of what the US does regularly,” Stamos tweeted.  

Were private companies or other governments hit with the malware?

Yes. Microsoft confirmed on Dec. 17 that it found indicators of the malware in its systems, after confirming several days earlier that the breach was affecting its customers. A Reuters report also said that Microsoft’s own systems were used to further the hacking campaign, but Microsoft denied this claim to news agencies. On Dec. 16, the company began quarantining the versions of Orion known to contain the malware, in order to cut hackers off from its customers’ systems.

FireEye also confirmed that it was infected with the malware and was seeing the infection in customer systems as well.

On Dec. 21, The Wall Street Journal said it had uncovered at least 24 companies that had installed the malicious software. These include tech companies Cisco, Intel, Nvidia, VMware and Belkin, according to the Journal. The hackers also reportedly had access to the California Department of State Hospitals and Kent State University.

It’s unclear which of SolarWinds’ other private sector customers saw malware infections. The company’s customer list includes large corporations, such as AT&T, Procter & Gamble and McDonald’s. The company also counts governments and private companies around the world as customers. FireEye says many of those customers were infected.

Correction, Dec. 23: This story has been updated to clarify that SolarWinds makes IT management software. An earlier version of the story misstated the purpose of its products.



Credit: www.cnet.com

Previous Post

Apple patents envision MacBook that wirelessly charges iPhone, iPad and Watch

Next Post

‘Deepfake porn images still give me nightmares’

Techie

Techie

Next Post

'Deepfake porn images still give me nightmares'

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Audio
  • Smart Devices
  • Tech

Tags

5G Amazon Android Android 11 Apple bharti airtel BJP China Congress coronavirus covid covid 19 Donald Trump Facebook FLIPKART Google Huawei India Instagram IOS iPhone iPhone 12 Jio Joe Biden mi Microsoft Motorola Narendra Modi OnePlus OPPO pandemic poco Realme redmi Samsung samsung galaxy s21 ultra Smartphones Social media Tech TikTok Twitter Vivo whatsapp Xiaomi youtube
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2020 Indi Tech News, Website By Maarich

No Result
View All Result
  • Home

© 2020 Indi Tech News, Website By Maarich