-
Wildfire flares up again in Greece as water bombers deployed
-
England, Wales had driest July on record: Met Office
-
Greece wildfire expert says season 'one of the worst' in a decade
-
French court rejects pro-Kremlin commentator's deportation appeal
-
Sandoz strikes US settlements to resolve generic drug price dispute
-
Oil slides, stocks rise on hopes of deal to end Mideast war
-
Israel conveys 'concerns' to US on Gaza plan, keeps up strikes on territory
-
EU chief urges 'united action' on borders after Ceuta migrant rush
-
Inside Capital Regency's Market Expansion and User Acquisition
-
Oil prices slide on hopes of deal to end Mideast war
-
Israel conveys 'concerns' to US on Gaza plan and keeps striking
-
Dortmund sign Greek teenager Karetsas from Genk
-
Bangladesh measles outbreak drives families into debt: aid groups
-
Detained Aung San Suu Kyi meets Red Cross delegate in Myanmar
-
BitMart、説明を迫られる:SNC SCANDIC COINの出金は8日経っても依然としてTXIDなし
-
설명 압박에 직면한 BitMart: 8일이 지나도 여전히 TXID가 없는 SNC SCANDIC COIN 출금
-
Seoul issues first 'severe heatwave warning' under new system
-
BitMart تحت ضغط لتقديم توضيحات: عمليات سحب عملة SNC SCANDIC COIN لا تزال بدون معرّف المعاملة (TXID) بعد مرور ثمانية أيام
-
BitMart змушений надати пояснення: виплати в SNC SCANDIC COIN через вісім днів досі без TXID
-
Welsh FA withdraws support for Infantino's FIFA re-election bid
-
BitMart 面臨解釋壓力:SNC SCANDIC COIN 提現八天後仍無 TXID
-
BitMart under pressure to explain: SNC SCANDIC COIN withdrawals still without a TXID after eight days
-
Cycling superstar Pogacar to ride in Vuelta
-
Iran denies negotiating with US after Trump announces talks
-
Water bombers take to skies as Greece battles wildfires
-
What Europe can learn from Australia's 'Black Summer' wildfires
-
Training the UK 'surgeons of the future' using robots
-
Oil prices sink on Iran hopes, yen gains after joint intervention
-
US, Japan join forces to boost yen
-
Wildfires raze neighborhoods in US northwest city of Spokane
-
Survivors recall blasts before deadly Indonesian ferry fire
-
Trump attorney general pick says has reached deal with senators after standoff
-
Detained Suu Kyi meets Red Cross official in Myanmar: president office
-
Star Australian broadcaster faces trial for sexual assault
-
Cuba state energy firm reports new nationwide blackout
-
Oil prices sink on Middle East hopes, yen extends gains after joint intervention
-
US, Japan support yen with first joint intervention since 2011
-
Millions of Thais banish the booze for Buddhist Lent
-
Pegula leads Eala as storms push Washington Open finals to Monday
-
Returning to 'Ted Lasso' after break 'effortless': Hannah Waddingham
-
US dairy industry muscles up thanks to protein craze
-
Trump says new Iran talks set to start after calling off massive attack
-
Leeds rally for 4-2 friendly win over Liverpool
-
Four Al-Fayed survivors told they were trafficking victims
-
Trump says US support for Japanese yen a 'signal of friendship'
-
Ariana Grande withdraws from London musical, seeks to 'step back'
-
Thorbjornsen earns maiden PGA win at Rocket Classic
-
Sudan army drone attack on Darfur court kills 35
-
Greaves steadies West Indies in second Test against Pakistan
-
At least 72 died in Spain's Ceuta migrant rush, Spain says
US, Microsoft warn Chinese hackers attacking 'critical' infrastructure
State-sponsored Chinese hackers have infiltrated critical US infrastructure networks, the United States, its Western allies and Microsoft said Wednesday while warning that similar espionage attacks could be occurring globally.
Microsoft highlighted Guam, a US territory in the Pacific Ocean with a vital military outpost, as one of the targets, but said "malicious" activity had also been detected elsewhere in the United States.
It said the hacking, dubbed "Volt Typhoon", had started in mid-2021 and was likely aimed at hampering the United States if there was conflict in the region.
"Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises," the statement said.
"In this campaign, the affected organizations span the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors.
"Observed behavior suggests that the threat actor intends to perform espionage and maintain access without being detected for as long as possible."
Microsoft's statement coincided with an advisory released by US, Australian, Canadian, New Zealand and UK authorities.
They said a "state-sponsored cyber actor" from China was behind Volt Typhoon and that the hacking was likely occurring globally.
"This activity affects networks across US critical infrastructure sectors, and the authoring agencies believe the actor could apply the same techniques against these and other sectors worldwide," the advisory said.
The United States and its allies said the activities involved "living off the land" tactics, which take advantage of built-in network tools to blend in with normal Windows systems.
It warned that the hacking could then incorporate legitimate system administration commands that appear "benign".
-'Highly sophisticated'-
Microsoft said Volt Typhoon tried to blend into normal network activity by routing traffic through compromised small office and home office network equipment, including routers, firewalls and VPN hardware.
"They have also been observed using custom versions of open-source tools," Microsoft said.
Microsoft and the security agencies released guidelines for organisations to try and detect and counter the hacking.
The director of the US Cybersecurity and Infrastructure Security Agency, Jen Easterly, also released a warning related to Volt Typhoon.
"For years, China has conducted operations worldwide to steal intellectual property and sensitive data from critical infrastructure organizations around the globe," Easterly said.
"Today's advisory, put out in conjunction with our US and international partners, reflects how China is using highly sophisticated means to target our nation's critical infrastructure.
"This joint advisory will give network defenders more insights into how to detect and mitigate this malicious activity."
China offered no immediate response to the allegations. But it routinely denies carrying out state-sponsored cyber attacks.
China in turn regularly accuses the United States of cyber espionage.
While China and Russia have long targeted critical infrastructure, Volt Typhoon offered new insights into Chinese hacking, according to John Hultquist, chief analyst at US cybersecurity company Mandiant.
"Chinese cyberthreat actors are unique among their peers in that they have not regularly resorted to destructive and disruptive cyberattacks," he said.
"As a result, their capability is quite opaque.This disclosure is a rare opportunity to investigate and prepare for this threat."
P.Anderson--BTB