La Derecha Diario logo
ESX logoInstagram logoYouTube logoTikTok logo
ARGENTINABOLIVIAECUADORISRAELMEXICOURUGUAY
  • ESXInstagramYouTubeTikTok
  • Secciones
  • ARGENTINA
  • BOLIVIA
  • ECUADOR
  • ISRAEL
  • MEXICO
  • URUGUAY
  • Países
  • La Derecha Diario logoLA DERECHA DIARIO
  • La Derecha Diario México logoLA DERECHA DIARIO MÉXICO
  • La Derecha Diario Uruguay logoLA DERECHA DIARIO URUGUAY
  • La Derecha Diario Ecuador logoLA DERECHA DIARIO ECUADOR
  • La Derecha Diario Bolívia logoLA DERECHA DIARIO BOLÍVIA
  • La Derechadiario República Dominicana logoLA DERECHADIARIO REPÚBLICA DOMINICANA
  • La Derecha Diario Israel logoLA DERECHA DIARIO ISRAEL
  • El Diario
  • QUIENES SOMOS
  • AUTORES
  • PUBLICIDAD
  • DONAR

A massive attack on Microsoft's servers puts China in the eye of the storm

A massive attack on Microsoft's servers puts China in the eye of the storm
A massive attack on Microsoft's servers by Chinese hackers has put the IT community on edge
porEditorial Team
Argentina

After a massive cyberattack on 'SharePoint' servers, Microsoft made strong accusations against the Chinese regime


A large-scale cyberespionage operation has compromised nearly 100 organizations through a critical vulnerability in on-premises Microsoft SharePoint servers, according to revelations by the firm Eye Security and the Shadowserver Foundation.

The attack, classified as "zero-day" for exploiting a previously unknown flaw, has caused international alarm due to its scope, sophistication, and possible origin linked to Chinese state actors.

Microsoft issued an alert on Saturday about "active attacks" against self-hosted versions of SharePoint, software widely used by companies and government institutions for document management and internal collaboration. Cloud-based versions of SharePoint were not affected.

Vaisha Bernard, director of hacking at Eye Security, indicated that a scan conducted together with Shadowserver identified nearly 100 compromised servers before the vulnerability became widely known. This figure is considered conservative, and there are concerns that malicious actors may have implanted additional backdoors in systems that have not yet been identified.

El objetivo del ataque fueron los servidores de SharePoint
El objetivo del ataque fueron los servidores de SharePoint

Shadowserver confirmed these findings and noted that the majority of those affected are located in the United States and Germany, including several government entities. The actual scope could be much greater: the Shodan tool identified more than 8,000 potentially exposed servers, while Shadowserver estimated more than 9,000.

Microsoft attributed with "high confidence" part of the attacks to actors with ties to China, in particular the groups known as Linen Typhoon, Violet Typhoon, and Storm-2603.

These groups have previously been identified as responsible for cyberespionage campaigns aimed at obtaining intellectual property and strategic data. Linen Typhoon, for example, has focused its attacks for more than a decade on government, defense, strategic planning, and human rights organizations.

Meanwhile, Violet Typhoon has targeted NGOs, universities, media outlets, and financial and health sectors in the United States, Europe, and East Asia.

Los ataques están relacionados a los grupos hackers chinos Linen Typhoon, Violet Typhoon y Storm 2603
Los ataques están relacionados a los grupos hackers chinos Linen Typhoon, Violet Typhoon y Storm 2603

The spokesperson for the Chinese embassy in Washington denied the accusations and stated that the country "firmly opposes all types of cyberattacks and cybercrimes" and rejected the lack of evidence in the allegations.

Nevertheless, cybersecurity experts confirmed that victims have been identified in multiple sectors and countries, and that the strikers used tactics similar to previous campaigns associated with Beijing.

According to the researchers, the attack consisted of sending malicious requests to vulnerable SharePoint servers, allowing the hackers to steal essential cryptographic material that was then used to maintain long-term access to the compromised systems.

This extended access turns the incident into a significant threat, not only because of data theft but also due to the potential for future manipulation or sabotage.

La embajada china en Estados Unidos negó cualquier relación con los ataques
La embajada china en Estados Unidos negó cualquier relación con los ataques

Microsoft released security updates and strongly recommended their immediate installation. However, experts such as Daniel Card from the firm PwnDefend warned that applying the patches is not enough.

Since strikers may have left backdoors before the vulnerability became known, organizations must assume they have been compromised and conduct thorough analyses of their systems.

The FBI, together with cybersecurity agencies from the United Kingdom and other countries, confirmed being aware of the attack and is working with private sector partners to mitigate its effects.

El FBI trabajará con el sector privado y otras agencias de inteligencia para hacer frente al ataque
El FBI trabajará con el sector privado y otras agencias de inteligencia para hacer frente al ataque


Noticias relacionadas

Luis d'Elia warned of an Iranian attack in Argentina

Luis d'Elia warned of an Iranian attack in Argentina

The FIA's stance on conflicts in the Middle East: 'Safety and well-being will guide our decisions'

The FIA's stance on conflicts in the Middle East: 'Safety and well-being will guide our decisions'

Atento Colapinto: Formula 1 will implement an important regulatory change that impacts racing in the rain

Atento Colapinto: Formula 1 will implement an important regulatory change that impacts racing in the rain

Milei's speech peaked in ratings and had a strong impact on streaming

Milei's speech peaked in ratings and had a strong impact on streaming

Qatar announced that it shot down two Iranian Su-24 warplanes

Qatar announced that it shot down two Iranian Su-24 warplanes

Corruption in AFA: Pablo Toviggino asked to annul his investigation into the case for withholding contributions

Corruption in AFA: Pablo Toviggino asked to annul his investigation into the case for withholding contributions

La Derecha Diario logo
TwitterInstagramYouTubeTikTok

Nosotros

  • Quienes Somos
  • Autores
  • Donar

Privacidad

  • Protección de datos
  • Canales
  • Sitemap

Contacto

  • info@derechadiario.com.ar
PUBLICIDAD