ZeroHour
CyberScooppublished ()ingested @snlyngaas

Mimecast confirms SolarWinds attackers breached security certificate, 'potentially exfiltrated' credentials

criticalData breach exploited in the wildimportance 60
Tagsbreach
Full article888 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Mimecast offers an attractive target for spies looking to burrow into high-value organizations

Mimecast
A view of Mimecast's North American offices. The email security provider said a "sophisticated threat actor" had breached its software certificate (Mimecast/Wikimedia Commons).

Email security firm Mimecast on Tuesday confirmed that the hackers behind the SolarWinds espionage campaign compromised a software certificate the firm uses to secure connections to Microsoft cloud services.

The revelation underscores how deeply embedded the suspected Russian hackers have been in major technology companies as part of a campaign that has also breached multiple U.S. federal agencies.

The hackers may have exfiltrated “certain encrypted service account credentials created by customers hosted” in the U.S. and the U.K., the new Mimecast statement reveals. The company said it wasn’t aware of the hackers decrypting or abusing any of the stolen credentials. But it still told its U.S. and U.K.-hosted customers to reset their credentials as a precaution.

Mimecast, which says it has 39,000 customers around the world, offers an attractive target for spies looking to burrow into high-value organizations. A stolen software certificate of this type could allow an intruder to lurk undetected and spy on Mimecast clients for months. The London-based firm has said the attackers apparently targeted “a low single-digit number” of customers.

“We have taken actions to isolate and remediate the identified threat, which we believe to be effective,” Mimecast said Tuesday.

Mimecast had disclosed a breach of its software certificate on Jan. 12, but did not name the culprit then.

Tony Cole, chief technology officer of the security firm Attivo Networks, said the Mimecast breach “could easily lead to successful attacks on Active Directory,” the Microsoft software that manages a computer network. “We must focus more on protecting Active Directory because it is a lot like the GPS of a Microsoft-centric enterprise.”

The broader hacking campaign has caused an uproar in Washington, and promises to be a big early test for the Biden administration’s cybersecurity policies. President Joe Biden has vowed a response to the cyber activity, which U.S. officials have said is “likely Russian in origin.” Moscow has denied involvement.

Biden raised the SolarWinds hacking campaign in a call Tuesday with Russian President Vladimir Putin, according to a White House statement. Further details were not immediately available.

Mimecast is one of many big tech firms to be implicated in the hacking campaign, which has also exploited bugged software made by SolarWinds, a Texas-based federal contractor. The attackers have viewed Microsoft’s source code and stolen the red-team tools that security firm FireEye uses to test clients’ defenses.

Cybersecurity firms continue to investigate the effect of the hacking campaign on their networks. Maryland-based Fidelis Cybersecurity said Tuesday that it had installed the trojanized SolarWinds software on one of its machines in May 2020, but that there was no indication the incident had impacted the firm’s networks.

SolarWinds’ software is also widely used in critical infrastructure sectors such as oil and gas and electricity.

Anti-virus firm Kaspersky said Tuesday that 27 of its customers in industrial sectors such as mining, energy and manufacturing had installed the malicious SolarWinds software. The victims were located around the world, from North America to the Asia Pacific.

More Scoops

PARIS, FRANCE – JUNE 04: In this photo illustration the GitHub logo is seen on the screen of an iPhone in front of a computer screen showing a Microsoft logo on June 04, 2018 in Paris, France. (Photo Illustration by Chesnot/Getty Images)

GitHub says internal repositories were impacted in poisoned VS Code extension attack

GitHub said late Tuesday that internal repositories were exfiltrated after an employee device was compromised through a poisoned Visual Studio Code extension, an incident that underscores the…

The SolarWinds Corp. logo is seen at the headquarters in Austin, Texas on April 15, 2021 in Austin, Texas. (Photo by SUZANNE CORDEIRO/AFP via Getty Images)

SEC drops case against SolarWinds tied to monumental breach

Signage at the headquarters of SAP AG, Germany’s largest software company on January 8, 2013 in Walldorf, Germany. (Photo by Thomas Lohnes/Getty Images)

SAP cyberattack widens, drawing Salt Typhoon and Volt Typhoon comparisons

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/mimecast-solarwinds-software-certificate-russia/