US nuclear weapons agency breached using Microsoft SharePoint hack

Date:

Share:


The US government agency in charge of designing and maintaining nuclear weapons was among those breached by a hack of Microsoft’s SharePoint server software, Bloomberg reported. However, attackers weren’t able to obtain any sensitive or classified information, according to an unnamed source with knowledge of the matter.

The breach occurred at the National Nuclear Security Administration, an arm of the Energy Department responsible for producing and dismantling nuclear arms. “On Friday, July 18th, the exploitation of a Microsoft SharePoint zero-day vulnerability began affecting the Department of Energy,” a spokesperson told Bloomberg. “A very small number of systems were impacted. All impacted systems are being restored.”

The exploit only affects SharePoint for on-premises servers. The Department of energy said it was minimally impacted because it widely uses Microsoft M365 cloud “and very capable cybersecurity systems,” the spokesperson added.

Microsoft blamed the attack on state-sponsored Chinese hackers. They reportedly exploited flaws in SharePoint document management software and were able to access and control systems and steal security credentials and tokens. “It’s a dream for ransomware operators,” Google’s Threat Intelligence Group said, adding that the flaw allows “persistent, unauthenticated access that can bypass future patching.”

Attackers also accessed the US Education Department and Florida’s Department of Revenue, along with government systems in other nations including the Middle East and Europe. Microsoft announced on Monday that it had released a new security patch “to mitigate active attacks targeting on-premises [and not online] servers.”



Source link

━ more like this

What if the Apple Watch looked like an iMac G3? This concept nails it

Apple‘s late-90s design era refuses to stay in the past, and a new Apple Watch concept inspired by the iMac G3 shows why...

2026 makes way for faster laptops, but at the cost of memory

CES (Consumer Electronics Show) has long served as a key venue for the introduction of new laptops. It also plays an important role...

Netflix has released a trailer for the Stranger Things finale

Tomorrow's the big day, and I don't just mean New Year's Eve. The series finale of Stranger Things airs tomorrow, and Netflix has...

1Password deal: Last chance to save 50 percent on our favorite password manager

If cleaning up your digital life is on your New Year's resolution list, we've got good news: 1Password is offering half off its...

Save $860 on a self-empty robot vacuum and mop, now just $269.99

If you’ve been waiting for a robot vacuum deal that’s more than a token discount, this one qualifies. The bObsweep UltraVision Pet self-empty...
spot_img