Thu May 9 13:00:12 2024
EVENTS
 FREE
SOFTWARE
INSTITUTE

POLITICS
JOBS
MEMBERS'
CORNER

MAILING
LIST

NYLXS Mailing Lists and Archives
NYLXS Members have a lot to say and share but we don't keep many secrets. Join the Hangout Mailing List and say your peice.

DATE 2023-07-01

HANGOUT

2024-05-09 | 2024-04-09 | 2024-03-09 | 2024-02-09 | 2024-01-09 | 2023-12-09 | 2023-11-09 | 2023-10-09 | 2023-09-09 | 2023-08-09 | 2023-07-09 | 2023-06-09 | 2023-05-09 | 2023-04-09 | 2023-03-09 | 2023-02-09 | 2023-01-09 | 2022-12-09 | 2022-11-09 | 2022-10-09 | 2022-09-09 | 2022-08-09 | 2022-07-09 | 2022-06-09 | 2022-05-09 | 2022-04-09 | 2022-03-09 | 2022-02-09 | 2022-01-09 | 2021-12-09 | 2021-11-09 | 2021-10-09 | 2021-09-09 | 2021-08-09 | 2021-07-09 | 2021-06-09 | 2021-05-09 | 2021-04-09 | 2021-03-09 | 2021-02-09 | 2021-01-09 | 2020-12-09 | 2020-11-09 | 2020-10-09 | 2020-09-09 | 2020-08-09 | 2020-07-09 | 2020-06-09 | 2020-05-09 | 2020-04-09 | 2020-03-09 | 2020-02-09 | 2020-01-09 | 2019-12-09 | 2019-11-09 | 2019-10-09 | 2019-09-09 | 2019-08-09 | 2019-07-09 | 2019-06-09 | 2019-05-09 | 2019-04-09 | 2019-03-09 | 2019-02-09 | 2019-01-09 | 2018-12-09 | 2018-11-09 | 2018-10-09 | 2018-09-09 | 2018-08-09 | 2018-07-09 | 2018-06-09 | 2018-05-09 | 2018-04-09 | 2018-03-09 | 2018-02-09 | 2018-01-09 | 2017-12-09 | 2017-11-09 | 2017-10-09 | 2017-09-09 | 2017-08-09 | 2017-07-09 | 2017-06-09 | 2017-05-09 | 2017-04-09 | 2017-03-09 | 2017-02-09 | 2017-01-09 | 2016-12-09 | 2016-11-09 | 2016-10-09 | 2016-09-09 | 2016-08-09 | 2016-07-09 | 2016-06-09 | 2016-05-09 | 2016-04-09 | 2016-03-09 | 2016-02-09 | 2016-01-09 | 2015-12-09 | 2015-11-09 | 2015-10-09 | 2015-09-09 | 2015-08-09 | 2015-07-09 | 2015-06-09 | 2015-05-09 | 2015-04-09 | 2015-03-09 | 2015-02-09 | 2015-01-09 | 2014-12-09 | 2014-11-09 | 2014-10-09 | 2014-09-09 | 2014-08-09 | 2014-07-09 | 2014-06-09 | 2014-05-09 | 2014-04-09 | 2014-03-09 | 2014-02-09 | 2014-01-09 | 2013-12-09 | 2013-11-09 | 2013-10-09 | 2013-09-09 | 2013-08-09 | 2013-07-09 | 2013-06-09 | 2013-05-09 | 2013-04-09 | 2013-03-09 | 2013-02-09 | 2013-01-09 | 2012-12-09 | 2012-11-09 | 2012-10-09 | 2012-09-09 | 2012-08-09 | 2012-07-09 | 2012-06-09 | 2012-05-09 | 2012-04-09 | 2012-03-09 | 2012-02-09 | 2012-01-09 | 2011-12-09 | 2011-11-09 | 2011-10-09 | 2011-09-09 | 2011-08-09 | 2011-07-09 | 2011-06-09 | 2011-05-09 | 2011-04-09 | 2011-03-09 | 2011-02-09 | 2011-01-09 | 2010-12-09 | 2010-11-09 | 2010-10-09 | 2010-09-09 | 2010-08-09 | 2010-07-09 | 2010-06-09 | 2010-05-09 | 2010-04-09 | 2010-03-09 | 2010-02-09 | 2010-01-09 | 2009-12-09 | 2009-11-09 | 2009-10-09 | 2009-09-09 | 2009-08-09 | 2009-07-09 | 2009-06-09 | 2009-05-09 | 2009-04-09 | 2009-03-09 | 2009-02-09 | 2009-01-09 | 2008-12-09 | 2008-11-09 | 2008-10-09 | 2008-09-09 | 2008-08-09 | 2008-07-09 | 2008-06-09 | 2008-05-09 | 2008-04-09 | 2008-03-09 | 2008-02-09 | 2008-01-09 | 2007-12-09 | 2007-11-09 | 2007-10-09 | 2007-09-09 | 2007-08-09 | 2007-07-09 | 2007-06-09 | 2007-05-09 | 2007-04-09 | 2007-03-09 | 2007-02-09 | 2007-01-09 | 2006-12-09 | 2006-11-09 | 2006-10-09 | 2006-09-09 | 2006-08-09 | 2006-07-09 | 2006-06-09 | 2006-05-09 | 2006-04-09 | 2006-03-09 | 2006-02-09 | 2006-01-09 | 2005-12-09 | 2005-11-09 | 2005-10-09 | 2005-09-09 | 2005-08-09 | 2005-07-09 | 2005-06-09 | 2005-05-09 | 2005-04-09 | 2005-03-09 | 2005-02-09 | 2005-01-09 | 2004-12-09 | 2004-11-09 | 2004-10-09 | 2004-09-09 | 2004-08-09 | 2004-07-09 | 2004-06-09 | 2004-05-09 | 2004-04-09 | 2004-03-09 | 2004-02-09 | 2004-01-09 | 2003-12-09 | 2003-11-09 | 2003-10-09 | 2003-09-09 | 2003-08-09 | 2003-07-09 | 2003-06-09 | 2003-05-09 | 2003-04-09 | 2003-03-09 | 2003-02-09 | 2003-01-09 | 2002-12-09 | 2002-11-09 | 2002-10-09 | 2002-09-09 | 2002-08-09 | 2002-07-09 | 2002-06-09 | 2002-05-09 | 2002-04-09 | 2002-03-09 | 2002-02-09 | 2002-01-09 | 2001-12-09 | 2001-11-09 | 2001-10-09 | 2001-09-09 | 2001-08-09 | 2001-07-09 | 2001-06-09 | 2001-05-09 | 2001-04-09 | 2001-03-09 | 2001-02-09 | 2001-01-09 | 2000-12-09 | 2000-11-09 | 2000-10-09 | 2000-09-09 | 2000-08-09 | 2000-07-09 | 2000-06-09 | 2000-05-09 | 2000-04-09 | 2000-03-09 | 2000-02-09 | 2000-01-09 | 1999-12-09

Key: Value:

Key: Value:

MESSAGE
DATE 2023-07-15
FROM Ruben Safir
SUBJECT Subject: [Hangout - NYLXS] Chinese haking and break ins of us officials and
wsj.com
Microsoft Email Hack Shows Greater Sophistication, Skill of China’s
Cyberspies
Dustin Volz, Robert McMillan and Josh Chin
7–8 minutes

The hack of email accounts of senior U.S. officials including the
commerce secretary is the latest feat from a network of Chinese
state-backed hackers whose leap in sophistication has alarmed U.S.
cybersecurity officials.

The espionage was aimed at a limited number of high-value U.S.
government and corporate targets. Though the number of victims appeared
to be small, the attack—and others unearthed in the past few months
linked to China—demonstrated a new level of skill from Beijing’s large
hacker army, and prompted concerns that the extent of its infiltration
into U.S. government and corporate networks is far greater than
currently known.

Even just a few years ago, Chinese hackers were known among
cybersecurity investigators for loud smash-and-grab heists of
intellectual property, military technology and even a database of U.S.
government employees’ personal information. The sometimes crude tactics,
while effective, were often geared toward collecting huge troves of data
rather than spying persistently on valuable targets, and typically left
traces that made the hackers easy to identify and guard against in the
future.

China’s hacker army used to be “noisy” and “rudimentary,” George Barnes,
the deputy director of the National Security Agency, said Thursday at an
intelligence conference. The new hack and others identified in the past
few months have shown that Beijing’s sophistication “continues to
increase,” he said.

The advances are driven by necessity. With competition between the U.S.
and China at its fiercest in decades, Beijing is eager for intelligence
on what Washington is thinking and doing, officials and security
analysts said. But recent progress in cybersecurity is forcing Chinese
hackers to be more discriminating about when and how they break in,
while heightened geopolitical tensions mean they have to be quieter as
they poke around.

The latest attack focused on the Microsoft email accounts of Commerce
Secretary Gina Raimondo, State Department officials and others not
publicly disclosed. It is already being rated by some security experts
as among the most technically sophisticated and stealthy ever
discovered, though many details—including how it began—haven’t been
shared by Microsoft. It and other recently disclosed cyber-espionage
operations suggest Chinese hackers can now burrow deep into high-level
computer networks and evade detection for months or even years.

The U.S. hasn’t formally linked the attack to China, though Microsoft
attributed it to a Chinese hacking group and officials and lawmakers
have said Beijing is responsible. China has denied the allegations.

China long relied on techniques such as blasting malicious spam at
hundreds of thousands of inboxes with little effort on the chance even a
single unsuspecting target would reveal a password. In some instances,
hackers would clumsily roam around a network until they tripped a
security alert that enabled defenders to quickly kick them out,
cybersecurity researchers said.

In 2015 the U.S. and China agreed to scale back cyberattacks, and
operations against Western targets appeared to decline. Then, in 2020
they began to increase again, only with much greater sophistication.

Fueled by the threat of ransomware attacks mostly emanating from Eastern
Europe, companies had gotten better at detecting attacks. So the Chinese
switched focus and began hitting devices on the edge of corporate
networks—hacks that were less likely to trigger security warnings, said
Charles Carmakal, the chief technology officer with Google’s Mandiant
cybersecurity group.

With the latest attack, the Chinese went a step further in their stealth
technique. They gained access to the guts of Microsoft’s cryptographic
protection system and used it to produce digital tokens—long strings of
numbers and letters that are stored in the browser and act as a digital
passport for Microsoft’s online services.

“They’re hitting where the log data doesn’t exactly light up like a
siren to tell you what’s wrong,” said Matt Durrin, director of training
and research at the security consulting firm LMG Security.

U.S. officials and Microsoft researchers disclosed on Tuesday that
hackers linked to China breached email accounts at more than two dozen
organizations globally, including some U.S. government agencies.
American officials later said that Raimondo and senior officials at the
State Department were among those in the government whose unclassified
accounts were compromised.

Microsoft shared new details about the hack in a technical blog post
Friday, but said that some aspects of how the hack unfolded remained
unclear to its security team.

The hack was because of a “a validation error in Microsoft code,” the
company said, but the blog post didn’t say when the bug was introduced.
It also didn’t explain how the hackers were able to obtain the
cryptographic tool they used to create their digital tokens. “The method
by which the actor acquired the key is a matter of ongoing
investigation,” the post said.

A Microsoft spokeswoman declined to answer further questions about the hack.

“It was a very advanced technique and capability and I imagine it was
very valuable to the actor that used it,” said Carmakal. That was likely
a reason why it appears to have been used on a small number of
high-value targets, he said. “The more they used it, the greater the
likelihood of getting caught.”

Cybersecurity specialists at the State Department detected the espionage
campaign in June, around the time when Secretary of State Antony Blinken
was planning a visit to Beijing to try to shore up deteriorating
relations between the two powers.

Blinken raised the hacking issue Thursday during a meeting in Jakarta
with China’s top foreign-policy official, State Department spokesman
Matt Miller said.

Blinken declined to answer directly a question during a news conference
Friday about whether his email account was compromised.

“I can’t discuss details of our response,” he said. “Most critically,
this incident remains under investigation.”

William Mauldin and Warren P. Strobel contributed to this article.

Write to Dustin Volz at dustin.volz-at-wsj.com, Robert McMillan at
robert.mcmillan-at-wsj.com and Josh Chin at Josh.Chin-at-wsj.com

Copyright ©2023 Dow Jones & Company, Inc. All Rights Reserved.
87990cbe856818d5eddac44c7b1cdeb8

Appeared in the July 15, 2023, print edition as 'Email Attack Shows Leap
in China Skills'.

What to Read Next


--
So many immigrant groups have swept through our town
that Brooklyn, like Atlantis, reaches mythological
proportions in the mind of the world - RI Safir 1998
http://www.mrbrklyn.com
DRM is THEFT - We are the STAKEHOLDERS - RI Safir 2002

http://www.nylxs.com - Leadership Development in Free Software
http://www.brooklyn-living.com

Being so tracked is for FARM ANIMALS and extermination camps,
but incompatible with living as a free human being. -RI Safir 2013
_______________________________________________
Hangout mailing list
Hangout-at-nylxs.com
http://lists.mrbrklyn.com/mailman/listinfo/hangout

  1. 2023-07-06 From: "Craig Topham, FSF" <info-at-fsf.org> Subject: [Hangout - NYLXS] Working together for free software licensing
  2. 2023-07-07 Touro Graduate School of Technology <info.gst-at-touro.edu> Subject: [Hangout - NYLXS] Workshop: Python 101
  3. 2023-07-10 Gabor Szabo <gabor-at-szabgab.com> Subject: [Hangout - NYLXS] [Perlweekly] #624 - TPRC 2023
  4. 2023-07-12 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] three felonies a day
  5. 2023-07-11 From: "DCAS, Office of Citywide Recruitment" <noreply-at-newsletters.nyc.gov> Subject: [Hangout - NYLXS] =?utf-8?q?NYC_Jobs_Newsletter_=E2=80=93_July_2?=
  6. 2023-07-12 Touro Graduate School of Technology <info.gst-at-touro.edu> Subject: [Hangout - NYLXS] ITP Workshop : Introduction to Chat GPT for
  7. 2023-07-15 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Chinese haking and break ins of us officials and
  8. 2023-07-16 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Nine Days and Fish
  9. 2023-07-17 Gabor Szabo <gabor-at-szabgab.com> Subject: [Hangout - NYLXS] [Perlweekly] #625 - Mohammad Sajid Anwar the new
  10. 2023-07-17 shulie <shulie_release-at-optimum.net> Subject: [Hangout - NYLXS] Anyone want to take this wih me?
  11. 2023-07-17 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Anyone want to take this wih me?
  12. 2023-07-20 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Fwd: LibrePlanet Wiki Edit Fest is on July 26:
  13. 2023-07-21 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] insanity
  14. 2023-07-21 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Tzfat
  15. 2023-07-22 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Thunderbird donations needed
  16. 2023-07-21 From: "Miriam Bastian, FSF" <info-at-fsf.org> Subject: [Hangout - NYLXS] Help us get twenty-five more associate members by
  17. 2023-07-27 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Blame the Doctors for Medical coss...
  18. 2023-07-27 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] covid-19 lab origin theory
  19. 2023-07-27 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Fwd: On The End Of Careers ...
  20. 2023-07-27 From: "Miriam Bastian, FSF" <info-at-fsf.org> Subject: [Hangout - NYLXS] From pro-democracy activist to minorities: Why
  21. 2023-07-25 From: "Greg Farough, FSF" <info-at-fsf.org> Subject: [Hangout - NYLXS] The campaigns team and the community work
  22. 2023-07-29 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] just buy it --- it is cheaper
  23. 2023-07-31 From: "Miriam Bastian, FSF" <info-at-fsf.org> Subject: [Hangout - NYLXS] When we work together, we achieve our goals

NYLXS are Do'ers and the first step of Doing is Joining! Join NYLXS and make a difference in your community today!