Microsoft said the recent wave of Exchange breaches are not connected to the last year’s SolarWinds attacks. AP
Microsoft said the recent wave of Exchange breaches are not connected to the last year’s SolarWinds attacks. AP
Microsoft said the recent wave of Exchange breaches are not connected to the last year’s SolarWinds attacks. AP
Microsoft said the recent wave of Exchange breaches are not connected to the last year’s SolarWinds attacks. AP

More than 30,000 entities compromised through Microsoft’s Exchange flaws


Alkesh Sharma
  • English
  • Arabic

Cyber-espionage group Hafnium has exploited Microsoft’s widely used email and calendar Exchange server, breaching more than 30,000 commercial and local government entities in the US.

Criminals took advantage of disclosed flaws in the Exchange platform, a report by KrebsOnSecurity said.

They also tried to remotely take control of email servers of hundreds of thousands of other organisations globally, it said.

Microsoft disclosed four vulnerabilities in its Exchange server in a blog last week.

The gaps let hackers have access to email accounts and install malicious codes on their servers.

The company accused Hafnium, which operates from China, of plotting attacks against Exchange users.

Microsoft issued emergency patches and called on customers to install them.

The company has said the attacks are limited only to business customers and do not affect individual users.

Lotem Finkelsteen, director of threat intelligence at American-Israeli software company Check Point, said the Microsoft attack “is relevant to all businesses using Outlook but not to individual consumers … it is a server issue that the cyber attackers exploited".

Tom Burt, Microsoft’s corporate vice president of customer security and trust, said Exchange was mainly used by business customers.

Mr Burt said there was "no evidence that Hafnium’s activities targeted individual consumers or that these exploits impact other Microsoft products".

Hafnium is a “highly skilled” and “sophisticated" group that steals information from various sectors, including medical researchers, law firms, education institutions, defence, think tanks and NGOs, Microsoft said.

“While Hafnium is based in China, it conducts its operations primarily from leased virtual private servers in the US,” it said.

Microsoft's UAE office referred The National to its blog and declined to comment further.

The US government is assessing the effect, a White House official said on Saturday.

"This is an active threat, still developing, and we urge network operators to take it very seriously," the official said.

China's Foreign Ministry said it “firmly opposes and combats cyber attacks and cyber theft in all forms”.

It said that accusing a particular nation is a “highly sensitive political issue”.

Vulnerabilities found in Exchange servers were “significant” and “could have far-reaching impacts”, said Jen Psaki, the White House press secretary.

“We are concerned that there are a large number of victims,” Ms Psaki said.

cyber
cyber

The increase in cyber threats has led to a surge in spending on cyber security, which is forecast to rise about 125 per cent to $363.05 billion by 2025 from 2019, research consultancy Mordor Intelligence said.

Industry experts said Exchange exploits were not limited to the US and could affect entities in other parts of the world.

The flaws are "quite severe even if we don't know the full scope of those attacks", Satnam Narang, staff research engineer at cyber-security company Tenable in Maryland, told The National.

“While Microsoft says that Hafnium primarily targets entities within the US, other researchers say they've seen these vulnerabilities being exploited by different threat actors targeting other regions,” Mr Narang said.

Cyber-security company FireEye has identified affected victims in the US including retailers, local governments, a university and an engineering company.

A South-East Asian government and a central Asian telecoms company were also hit.

“In addition to patching as soon as possible, we recommend organisations review their systems for evidence of exploitation that may have occurred prior to the deployment of the patches,” said Charles Carmakal, senior vice president and chief technology officer of FireEye.

Microsoft has said the recent wave of breaches are "in no way connected" to last year's SolarWinds attacks by Russian hackers, which compromised nine US federal agencies and almost 100 businesses.

"State-sponsored hacking groups are exploiting critical Exchange bugs that Microsoft has already patched last week," Avinash Advani, founder and chief executive of Dubai cyber-security company CyberKnight, told The National.

"The disclosure will attract other threat actors looking to compromise unpatched servers.”

F1 The Movie

Starring: Brad Pitt, Damson Idris, Kerry Condon, Javier Bardem

Director: Joseph Kosinski

Rating: 4/5

THE BIO: Martin Van Almsick

Hometown: Cologne, Germany

Family: Wife Hanan Ahmed and their three children, Marrah (23), Tibijan (19), Amon (13)

Favourite dessert: Umm Ali with dark camel milk chocolate flakes

Favourite hobby: Football

Breakfast routine: a tall glass of camel milk

Benefits of first-time home buyers' scheme
  • Priority access to new homes from participating developers
  • Discounts on sales price of off-plan units
  • Flexible payment plans from developers
  • Mortgages with better interest rates, faster approval times and reduced fees
  • DLD registration fee can be paid through banks or credit cards at zero interest rates
The specs: Macan Turbo

Engine: Dual synchronous electric motors
Power: 639hp
Torque: 1,130Nm
Transmission: Single-speed automatic
Touring range: 591km
Price: From Dh412,500
On sale: Deliveries start in October

Essentials

The flights

Etihad (etihad.ae) and flydubai (flydubai.com) fly direct to Baku three times a week from Dh1,250 return, including taxes. 
 

The stay

A seven-night “Fundamental Detox” programme at the Chenot Palace (chenotpalace.com/en) costs from €3,000 (Dh13,197) per person, including taxes, accommodation, 3 medical consultations, 2 nutritional consultations, a detox diet, a body composition analysis, a bio-energetic check-up, four Chenot bio-energetic treatments, six Chenot energetic massages, six hydro-aromatherapy treatments, six phyto-mud treatments, six hydro-jet treatments and access to the gym, indoor pool, sauna and steam room. Additional tests and treatments cost extra.

Dust and sand storms compared

Sand storm

  • Particle size: Larger, heavier sand grains
  • Visibility: Often dramatic with thick "walls" of sand
  • Duration: Short-lived, typically localised
  • Travel distance: Limited 
  • Source: Open desert areas with strong winds

Dust storm

  • Particle size: Much finer, lightweight particles
  • Visibility: Hazy skies but less intense
  • Duration: Can linger for days
  • Travel distance: Long-range, up to thousands of kilometres
  • Source: Can be carried from distant regions
COMPANY%20PROFILE
%3Cp%3E%3Cstrong%3ECompany%20name%3A%3C%2Fstrong%3E%20Clinicy%3Cbr%3E%3Cstrong%3EStarted%3A%3C%2Fstrong%3E%202017%3Cbr%3E%3Cstrong%3EFounders%3A%3C%2Fstrong%3E%20Prince%20Mohammed%20Bin%20Abdulrahman%2C%20Abdullah%20bin%20Sulaiman%20Alobaid%20and%20Saud%20bin%20Sulaiman%20Alobaid%3Cbr%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20Riyadh%3Cbr%3E%3Cstrong%3ENumber%20of%20staff%3A%3C%2Fstrong%3E%2025%3Cbr%3E%3Cstrong%3ESector%3A%3C%2Fstrong%3E%20HealthTech%3Cbr%3E%3Cstrong%3ETotal%20funding%20raised%3A%3C%2Fstrong%3E%20More%20than%20%2410%20million%3Cbr%3E%3Cstrong%3EInvestors%3A%3C%2Fstrong%3E%20Middle%20East%20Venture%20Partners%2C%20Gate%20Capital%2C%20Kafou%20Group%20and%20Fadeed%20Investment%3C%2Fp%3E%0A
Vidaamuyarchi

Director: Magizh Thirumeni

Stars: Ajith Kumar, Arjun Sarja, Trisha Krishnan, Regina Cassandra

Rating: 4/5

 

The specs
  • Engine: 3.9-litre twin-turbo V8
  • Power: 640hp
  • Torque: 760nm
  • On sale: 2026
  • Price: Not announced yet
Company info

Company name: Entrupy 

Co-founders: Vidyuth Srinivasan, co-founder/chief executive, Ashlesh Sharma, co-founder/chief technology officer, Lakshmi Subramanian, co-founder/chief scientist

Based: New York, New York

Sector/About: Entrupy is a hardware-enabled SaaS company whose mission is to protect businesses, borders and consumers from transactions involving counterfeit goods.  

Initial investment/Investors: Entrupy secured a $2.6m Series A funding round in 2017. The round was led by Tokyo-based Digital Garage and Daiwa Securities Group's jointly established venture arm, DG Lab Fund I Investment Limited Partnership, along with Zach Coelius. 

Total customers: Entrupy’s customers include hundreds of secondary resellers, marketplaces and other retail organisations around the world. They are also testing with shipping companies as well as customs agencies to stop fake items from reaching the market in the first place. 

FROM%20THE%20ASHES
%3Cp%3EDirector%3A%20Khalid%20Fahad%3C%2Fp%3E%0A%3Cp%3EStarring%3A%20Shaima%20Al%20Tayeb%2C%20Wafa%20Muhamad%2C%20Hamss%20Bandar%3C%2Fp%3E%0A%3Cp%3ERating%3A%203%2F5%3C%2Fp%3E%0A
CHATGPT%20ENTERPRISE%20FEATURES
%3Cp%3E%E2%80%A2%20Enterprise-grade%20security%20and%20privacy%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20Unlimited%20higher-speed%20GPT-4%20access%20with%20no%20caps%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20Longer%20context%20windows%20for%20processing%20longer%20inputs%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20Advanced%20data%20analysis%20capabilities%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20Customisation%20options%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20Shareable%20chat%20templates%20that%20companies%20can%20use%20to%20collaborate%20and%20build%20common%20workflows%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20Analytics%20dashboard%20for%20usage%20insights%3C%2Fp%3E%0A%3Cp%3E%E2%80%A2%20Free%20credits%20to%20use%20OpenAI%20APIs%20to%20extend%20OpenAI%20into%20a%20fully-custom%20solution%20for%20enterprises%3C%2Fp%3E%0A
Coming 2 America

Directed by: Craig Brewer

Starring: Eddie Murphy, Arsenio Hall, Jermaine Fowler, Leslie Jones

3/5 stars

It's up to you to go green

Nils El Accad, chief executive and owner of Organic Foods and Café, says going green is about “lifestyle and attitude” rather than a “money change”; people need to plan ahead to fill water bottles in advance and take their own bags to the supermarket, he says.

“People always want someone else to do the work; it doesn’t work like that,” he adds. “The first step: you have to consciously make that decision and change.”

When he gets a takeaway, says Mr El Accad, he takes his own glass jars instead of accepting disposable aluminium containers, paper napkins and plastic tubs, cutlery and bags from restaurants.

He also plants his own crops and herbs at home and at the Sheikh Zayed store, from basil and rosemary to beans, squashes and papayas. “If you’re going to water anything, better it be tomatoes and cucumbers, something edible, than grass,” he says.

“All this throwaway plastic - cups, bottles, forks - has to go first,” says Mr El Accad, who has banned all disposable straws, whether plastic or even paper, from the café chain.

One of the latest changes he has implemented at his stores is to offer refills of liquid laundry detergent, to save plastic. The two brands Organic Foods stocks, Organic Larder and Sonnett, are both “triple-certified - you could eat the product”.  

The Organic Larder detergent will soon be delivered in 200-litre metal oil drums before being decanted into 20-litre containers in-store.

Customers can refill their bottles at least 30 times before they start to degrade, he says. Organic Larder costs Dh35.75 for one litre and Dh62 for 2.75 litres and refills will cost 15 to 20 per cent less, Mr El Accad says.

But while there are savings to be had, going green tends to come with upfront costs and extra work and planning. Are we ready to refill bottles rather than throw them away? “You have to change,” says Mr El Accad. “I can only make it available.”

$1,000 award for 1,000 days on madrasa portal

Daily cash awards of $1,000 dollars will sweeten the Madrasa e-learning project by tempting more pupils to an education portal to deepen their understanding of math and sciences.

School children are required to watch an educational video each day and answer a question related to it. They then enter into a raffle draw for the $1,000 prize.

“We are targeting everyone who wants to learn. This will be $1,000 for 1,000 days so there will be a winner every day for 1,000 days,” said Sara Al Nuaimi, project manager of the Madrasa e-learning platform that was launched on Tuesday by the Vice President and Ruler of Dubai, to reach Arab pupils from kindergarten to grade 12 with educational videos.  

“The objective of the Madrasa is to become the number one reference for all Arab students in the world. The 5,000 videos we have online is just the beginning, we have big ambitions. Today in the Arab world there are 50 million students. We want to reach everyone who is willing to learn.”

The%C2%A0specs%20
%3Cp%3E%0D%3Cstrong%3EEngine%3A%20%3C%2Fstrong%3E6-cylinder%2C%204.8-litre%20%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3E5-speed%20automatic%20and%20manual%0D%3Cbr%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E280%20brake%20horsepower%20%0D%3Cbr%3E%3Cstrong%3ETorque%3A%20%3C%2Fstrong%3E451Nm%20%0D%3Cbr%3E%3Cstrong%3EPrice%3A%20%3C%2Fstrong%3Efrom%20Dh153%2C00%0D%3Cbr%3E%3Cstrong%3EOn%20sale%3A%20%3C%2Fstrong%3Enow%3C%2Fp%3E%0A