欧洲新闻网 | 中国 | 国际 | 社会 | 娱乐 | 时尚 | 民生 | 科技 | 旅游 | 体育 | 财经 | 健康 | 文化 | 艺术 | 人物 | 家居 | 公益 | 视频 | 华人 | 有福之州
主页 > 头条 > 正文


2023-07-13 17:46 -ABC  -  403531








虽然国务院发言人马修·米勒(Matthew Miller)今天在讲台上对此次入侵事件说得不多,但知情官员表示,黑客攻击始于5月,但直到6月中旬才被发现,尽管当月早些时候国务院的电子邮件系统中存在广泛的问题——可能错过了警告信号。


“微软通知该部门对微软的Office 365系统的妥协,该部门立即采取行动予以回应,”商务部发言人告诉美国广播公司新闻。“我们正在监控我们的系统,如果发现任何进一步的活动,我们将立即做出反应。该部门保持强大的网络安全保护,我们更新这些保护以应对快速发展的网络安全形势。”


“2023年6月16日,根据客户报告的信息,微软开始对异常邮件活动进行调查,”该警报写道。“在接下来的几周内,我们的调查显示,从2023年5月15日开始,Storm-0558获得了大约25个组织的电子邮件数据,以及少量可能与这些组织有关联的个人的相关消费者帐户。他们通过使用伪造的身份验证令牌来访问用户电子邮件,并使用获得的Microsoft account (MSA)消费者签名密钥来做到这一点。微软已经为所有客户缓解了这种攻击。”

美国联邦调查局(FBI)和网络安全与基础设施安全局(cyber Security and infra structure Security Agency)官员当天早些时候告诉记者,微软“迅速”采取行动,减轻了黑客攻击政府电子邮件造成的损害。







“微软确定APT actors从少数账户中访问并泄露了非机密的Exchange Online Outlook数据,”该警告称。“APT参与者使用微软帐户(MSA)消费者密钥来伪造令牌,以冒充消费者和企业用户。Microsoft通过首先阻止使用获取的密钥颁发的令牌,然后替换密钥以防止继续误用来解决该问题。


Commerce Secretary Gina Raimondo's emails hacked in Microsoft cyber breach: Source

Commerce Secretary Gina Raimondo's emails were hacked as part of the Microsoft cyber breach, according to a source familiar with the investigation.

Microsoft's Outlook systems were breached by Chinese hackers, according to the company. The breach was discovered in May.

Raimondo’s Commerce Department has been imposing sanctions on China, and she met with her Chinese counterpart in May, promising better relations.

This isn't the first time a cabinet-level secretary's emails were breached. The emails of former Acting Secretary of Homeland Security Chad Wolf were compromised during the SolarWinds hack of 2020, which is widely considered one of the worst breaches in U.S. history.

SolarWinds was a hack that was carried out by the Russian nation-state actor Nobelium, Microsoft said in 2021.

Raimondo is the only cabinet secretary so far to have their emails hacked in this particular breach.

The State Department, though, was also impacted by the latest cyber breach.

While State Department spokesperson Matthew Miller could say little more about the breach from the podium today, officials familiar with the matter say the hack began in May but was not identified until mid-June, even though there were widespread issues within the department’s email systems earlier that month -- potentially missed warning signs.

The Department of Commerce is the second agency impacted by the Microsoft 365 hack by the Chinese hackers.

“Microsoft notified the Department of a compromise to Microsoft’s Office 365 system, and the Department took immediate action to respond,” a commerce department spokesperson told ABC News. “We are monitoring our systems and will respond promptly should any further activity be detected. The Department maintains strong cyber security protections, which we update to address a rapidly evolving cyber security landscape.”

In an alert sent Tuesday night, Microsoft said China was able to gain email data from 25 organizations.

"On June 16, 2023, based on customer reported information, Microsoft began an investigation into anomalous mail activity," the alert read. "Over the next few weeks, our investigation revealed that beginning on May 15, 2023, Storm-0558 gained access to email data from approximately 25 organizations, and a small number of related consumer accounts of individuals likely associated with these organizations. They did this by using forged authentication tokens to access user email using an acquired Microsoft account (MSA) consumer signing key. Microsoft has completed mitigation of this attack for all customers."

FBI and Cybersecurity and Infrastructure Security Agency officials told reporters earlier in the day that Microsoft acted “swiftly” to mitigate the damage done by the hacking of government emails.

The attack, officials said, was targeted and lasted for about a month.

“The targeting was intentional. This was an attack that was limited in scope and was not an attempt to compromise a broad array of organizations or accounts, as we have seen in other types of campaigns,” the CISA official said.

The adversary that hacked the emails is China, according to Microsoft, but officials did not give any U.S. government attribution.

“As Microsoft has articulated the timeline from the first known intrusion to the time when Microsoft remediated this attack vector was approximately one month, that does not mean that the duration of the intrusion for all victims was one month. And we do understand that some were shorter than one month, in some cases a number of days,” a senior CISA official said.

The CISA official said there was nothing classified that was compromised during the attack.

CISA and the FBI went into detail about how the Chinese carried out the attack in an alert on Wednesday.

“Microsoft determined that APT actors accessed and exfiltrated unclassified Exchange Online Outlook data from a small number of accounts,” the alert read. “The APT actors used a Microsoft account (MSA) consumer key to forge tokens to impersonate consumer and enterprise users. Microsoft remediated the issue by first blocking tokens issued with the acquired key and then replacing the key to prevent continued misuse.”

On Thursday, China’s Foreign Ministry spokesperson Wang Wenbin was asked about Microsoft’s claims that China is behind the hacking. He did not address the claim, but instead responded by claiming the U.S. is “the world’s biggest hacking empire and global cyber thief.”






关于我们| 联系我们| 广告服务| 供稿服务| 法律声明| 招聘信息| 网站地图

本网站所刊载信息,不代表美国新闻网的立场和观点。 刊用本网站稿件,务经书面授权。

美国新闻网由欧洲华文电视台美国站主办 www.uscntv.com

[部分稿件来源于网络,如有侵权请及时联系我们] [邮箱:uscntv@outlook.com]