NSA warns Russia-linked Sandworm hacking group has been actively exploiting a now-patched flaw in Exim mail transfer agent since Aug., exposing ~2.5M servers
The U.S. National Security Agency (NSA) says that Russian military threat actors known as Sandworm Team have been exploiting …
BleepingComputer Sergiu Gatlan
Related Coverage
- Exim Mail Transfer Agent Actively Exploited by Russian GRU Cyber Actors National Security …
- Russian hackers are exploiting bug that gives control of US servers Ars Technica · Dan Goodin
- NSA: Russia's Sandworm Hackers Have Hijacked Mail Servers Wired · Andy Greenberg
- U.S. Accuses Russian Military Hackers of Attack on Email Servers New York Times
- NSA Publishes IOCs Associated With Russian Targeting of Exim Servers SecurityWeek · Ionut Arghire
- Exim Vulnerability: GRU Widely Exploited Critical 2019 Bug, Warns NSA Computer Business Review · Conor Reynolds
- NSA warns of new cyberattacks by Russian military hackers CBS News · Olivia Gazis
- FCW Insider: May 29 — Russian hackers have exploited … Federal Computer Week
Discussion
-
@nsacyber
@nsacyber
on x
Sandworm Team, Russian GRU Main Center for Special Technologies actors, continue to exploit Exim mail transfer agent #vulnerability, CVE-2019-10149. Patch to the latest version to protect your networks. Learn more here: https://www.nsa.gov/... https://twitter.com/...
-
@karolcummins
Karol Cummins
on x
U.S. Accuses Russian Military Hackers of Attack on Email Servers The unusually public complaint showed that American spy agencies are becoming more aggressive in calling out Moscow's interference as the presidential election approaches. https://www.nytimes.com/...
-
@kevincollier
Kevin Collier
on x
I want your rampant speculation: by the end of 2020, will we see a dump or leak of a politically important person's emails, hacked via this particular exploit? https://www.nbcnews.com/...
-
@adam_k_levin
Adam Levin
on x
A Russian hacking group tied to power-grid attacks in Ukraine, and other nefarious Kremlin operations is exploiting a vulnerability that allows it to take control of computers operated by the US government and its partners. https://arstechnica.com/...
-
@davidcorndc
David Corn
on x
The NSA publicly announced the Russian hackers who attacked the 2016 election are still active. So what is Trump going to do to protect the 2020 election from them? (That's known as a rhetorical question.) https://www.nbcnews.com/...
-
@nsagov
NSA
on x
Russian GRU actors, Sandworm Team, are exploiting a #vulnerability present in unpatched Exim mail transfer agent software. Protect your networks by checking out the latest from @NSACyber https://twitter.com/...
-
@natashabertrand
Natasha Bertrand
on x
The same Russian intelligence unit that leaked Democrats' files in 2016 is engaged in an ongoing email hacking campaign, the National Security Agency announced Thursday. via @kevincollier https://www.nbcnews.com/...
-
@markhughesfilms
Mark Hughes
on x
It's an act of war, & if we had a real govt that wasn't acting as treasonous puppets for the attacker, then they would treat it as such. https://twitter.com/...
-
@malwarejake
Jake Williams
on x
One of the big questions I have about the NSA release is “why now?” The vuln was first exploited in the wild in June 2019 (days after release). The report claims that Sandworm has been exploiting it since August. So what changed that made it necessary to talk about this now? 1/ h…