Mimecast confirms SolarWinds attackers breached security certificate, 'potentially exfiltrated' credentials
Full article888 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Mimecast offers an attractive target for spies looking to burrow into high-value organizations
Email security firm Mimecast on Tuesday confirmed that the hackers behind the SolarWinds espionage campaign compromised a software certificate the firm uses to secure connections to Microsoft cloud services.
The revelation underscores how deeply embedded the suspected Russian hackers have been in major technology companies as part of a campaign that has also breached multiple U.S. federal agencies.
The hackers may have exfiltrated “certain encrypted service account credentials created by customers hosted” in the U.S. and the U.K., the new Mimecast statement reveals. The company said it wasn’t aware of the hackers decrypting or abusing any of the stolen credentials. But it still told its U.S. and U.K.-hosted customers to reset their credentials as a precaution.
Mimecast, which says it has 39,000 customers around the world, offers an attractive target for spies looking to burrow into high-value organizations. A stolen software certificate of this type could allow an intruder to lurk undetected and spy on Mimecast clients for months. The London-based firm has said the attackers apparently targeted “a low single-digit number” of customers.
“We have taken actions to isolate and remediate the identified threat, which we believe to be effective,” Mimecast said Tuesday.
Mimecast had disclosed a breach of its software certificate on Jan. 12, but did not name the culprit then.
Tony Cole, chief technology officer of the security firm Attivo Networks, said the Mimecast breach “could easily lead to successful attacks on Active Directory,” the Microsoft software that manages a computer network. “We must focus more on protecting Active Directory because it is a lot like the GPS of a Microsoft-centric enterprise.”
The broader hacking campaign has caused an uproar in Washington, and promises to be a big early test for the Biden administration’s cybersecurity policies. President Joe Biden has vowed a response to the cyber activity, which U.S. officials have said is “likely Russian in origin.” Moscow has denied involvement.
Biden raised the SolarWinds hacking campaign in a call Tuesday with Russian President Vladimir Putin, according to a White House statement. Further details were not immediately available.
Mimecast is one of many big tech firms to be implicated in the hacking campaign, which has also exploited bugged software made by SolarWinds, a Texas-based federal contractor. The attackers have viewed Microsoft’s source code and stolen the red-team tools that security firm FireEye uses to test clients’ defenses.
Cybersecurity firms continue to investigate the effect of the hacking campaign on their networks. Maryland-based Fidelis Cybersecurity said Tuesday that it had installed the trojanized SolarWinds software on one of its machines in May 2020, but that there was no indication the incident had impacted the firm’s networks.
SolarWinds’ software is also widely used in critical infrastructure sectors such as oil and gas and electricity.
Anti-virus firm Kaspersky said Tuesday that 27 of its customers in industrial sectors such as mining, energy and manufacturing had installed the malicious SolarWinds software. The victims were located around the world, from North America to the Asia Pacific.
More Scoops
GitHub says internal repositories were impacted in poisoned VS Code extension attack
GitHub said late Tuesday that internal repositories were exfiltrated after an employee device was compromised through a poisoned Visual Studio Code extension, an incident that underscores the…
SEC drops case against SolarWinds tied to monumental breach
SAP cyberattack widens, drawing Salt Typhoon and Volt Typhoon comparisons
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/mimecast-solarwinds-software-certificate-russia/