Most of Canada to receive emergency alert test today
The federal government will test its capacity to issue emergency alerts today, with the exception of Ontario, where the test will take place on May 15.
Microsoft said Monday the same Russia-backed hackers responsible for the 2020 SolarWinds breach continue to attack the global technology supply chain and have been relentlessly targeting cloud service companies and others since summer.
The group, which Microsoft calls Nobelium, has employed a new strategy to piggyback on the direct access that cloud service resellers have to their customers' IT systems, hoping to "more easily impersonate an organization's trusted technology partner to gain access to their downstream customers." Resellers act as intermediaries between giant cloud companies and their ultimate customers, managing and customizing accounts.
"Fortunately, we have discovered this campaign during its early stages, and we are sharing these developments to help cloud service resellers, technology providers, and their customers take timely steps to help ensure Nobelium is not more successful," Tom Burt, a Microsoft vice president, said in a blog post.
The Biden administration downplayed Microsoft's announcement. A U.S. government official briefed on the issue who insisted on anonymity to discuss the government's response noted that "the activities described were unsophisticated password spray and phishing, run-of-the mill operations for the purpose of surveillance that we already know are attempted every day by Russia and other foreign governments."
The Russian Embassy did not immediately reply to a request for comment.
U.S. and Russian ties have already been strained this year over a string of high-profile ransomware attacks against U.S. targets launched by Russia-based cyber gangs. U.S. President Joe Biden has warned to Russian President Vladimir Putin to get him to crack down on ransomware criminals, but several top administration cybersecurity officials have said recently that they have seen no evidence of that.
Supply chain attacks allow hackers to steal information from multiple targets by breaking into a single product they all use. The U.S. government has previously blamed Russia's SVR foreign intelligence agency for the SolarWinds hack, a supply-chain hack which went undetected for most of 2020, compromised several federal agencies and badly embarrassing Washington.
The hacking campaign is called SolarWinds after the U.S. software company whose product was used in that effort. The Biden administration in April placed new sanctions against six Russian companies that support the country's cyber efforts in response to the SolarWinds hack.
Microsoft has been observing Nobelium's latest campaign since May and has notified more than 140 companies targeted by the group, with as many as 14 believed to have been compromised. The attacks have been increasingly relentless since July, with Microsoft noting that it had informed 609 customers that they had been attacked 22,868 times by Nobelium, with a success rate in the low single digits. That's more attacks than Microsoft had flagged from all nation-state actors in the previous three years.
"Russia is trying to gain long-term, systematic access to a variety of points in the technology supply chain and establish a mechanism for surveilling -- now or in the future -- targets of interest to the Russian government," Burt said.
Microsoft did not name any of the hackers' targets in their latest campaign. But cybersecurity firm Mandiant said it had seen victims in both Europe and North America.
Mandiant Chief Technology Officer Charles Carmakal said the hackers' method of going after resellers make detection difficult.
"It shifts the initial intrusion away from the ultimate targets, which in some situations are organizations with more mature cyber defenses, to smaller technology partners with less mature cyber defenses," he said.
------
AP Business Writer Matt Ott in Silver Spring, Maryland, contributed to this report.
The federal government will test its capacity to issue emergency alerts today, with the exception of Ontario, where the test will take place on May 15.
Prince Harry, the Duke of Sussex, has made headlines with his recent arrival in the U.K., this time to celebrate all things Invictus. But upon the prince landing in the U.K., we have already had confirmation that King Charles III won't have time to see his youngest son during his brief visit.
An Ontario man found out that a line of credit he thought was insured actually isn't after his wife of 50 years died.
After more than a century, Boy Scouts of America is rebranding as Scouting America, another major shakeup for an organization that once proudly resisted change.
With Donald Trump sitting just feet away, Stormy Daniels testified Tuesday at the former president's hush money trial about a sexual encounter the porn actor says they had in 2006 that resulted in her being paid to keep silent during the presidential race 10 years later.
In March, Indonesian officials and local fishermen rescued 75 people from the overturned hull of a boat off the coast of Indonesia. Until now, little was known about why the boat capsized.
An Ontario woman said it would have been impossible to buy a house without her mother – an anecdote that animates the fact that over 17 per cent of Canadian homeowners born in the ‘90s own their property with their parents, according to a new report.
Canadian immigrants threatened by hostile regimes are urging parliamentarians to quickly pass the 'Countering Foreign Interference Act' so they can feel safe living in their adopted home.
A long-simmering feud between hip-hop superstars Drake and Kendrick Lamar reached a boiling point in recent days as the pair traded increasingly personal insults on a succession of diss tracks. Here’s a quick overview of what’s behind the ongoing beef.
An Ontario man says he paid more than $7,700 for a luxury villa he found on a popular travel website -- but the listing was fake.
Whether passionate about Poirot or hungry for Holmes, Winnipeg mystery obsessives have had a local haunt for over 30 years in which to search out their latest page-turners.
Eighty-two-year-old Susan Neufeldt and 90-year-old Ulrich Richter are no spring chickens, but their love blossomed over the weekend with their wedding at Pine View Manor just outside of Rosthern.
Alberta Ballet's double-bill production of 'Der Wolf' and 'The Rite of Spring' marks not only its final show of the season, but the last production for twin sisters Alexandra and Jennifer Gibson.
A mother goose and her goslings caused a bit of a traffic jam on a busy stretch of the Trans-Canada Highway near Vancouver Saturday.
A British Columbia mayor has been censured by city council – stripping him of his travel and lobbying budgets and removing him from city committees – for allegedly distributing a book that questions the history of Indigenous residential schools in Canada.
Three men in Quebec from the same family have fathered more than 600 children.
A group of SaskPower workers recently received special recognition at the legislature – for their efforts in repairing one of Saskatchewan's largest power plants after it was knocked offline for months following a serious flood last summer.
A police officer on Montreal's South Shore anonymously donated a kidney that wound up drastically changing the life of a schoolteacher living on dialysis.