Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Click for more information, or
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
GET RECOGNIZED.
Let an ISACA® certification
elevate your career.

Register today and save
Microsoft/Windows
DDoS Protection Powered By Verisign
Average Rating:
Rate this article:  
Syrian Electronic Army Hacks Microsoft -- Again

Syrian Electronic Army Hacks Microsoft -- Again
By Jennifer LeClaire

Share
Share on Facebook Share on Twitter Share on Linkedin Share on Google Plus

The attacks against Microsoft by the Syrian Electronic Army aren’t particularly sophisticated or novel. In going after Microsoft, the Syrian Electronic Army has used well-known breaching tactics. But the fact that the hacktivist group is continually successful shows that the industry needs to do a better job guarding against these tactics.
 


One particular hacktivist group seems to have a bone to pick with mighty Microsoft. First, the Syrian Electronic Army (SEA) hijacked a few of Redmond’s Twitter accounts. Next, the group invaded the company’s official blog. Now, the SEA has hacked into Microsoft’s Office Blogs site.

The hackers took to Twitter with proof positive in the form of a screenshot of the Microsoft Office Blog site. The SEA article was titled “Hacked by the Syrian Electronic Army” and was placed next to “Office 15-Minute Webinars” and “Top 5 Reasons to attend Sharepoint Conference 2014” on the blog’s home page.

Microsoft was quick to take down the article, but Google searchers can still find the cached image. The attack comes as Microsoft rolled out a new design for its Office Blog site -- complete with a new content management system (CMS) -- on Monday and the SEA’s Twitter message reads, “Dear @Microsoft, Changing the CMS will not help you if your employees are hacked and they don’t know about that.”

Breaking the Pattern

“A targeted cyberattack temporarily affected the Microsoft Office blog,” the company said in a statement. “The account was quickly reset and we can confirm that no customer information was compromised.”

We caught up with Ken Pickering, director of Engineering at CORE Security, to get his take on the Microsoft attacks. He told us the attacks aren’t particularly sophisticated or novel. The SEA, he noted, uses well-known breaching tactics and the fact that they are continually successful shows that the industry needs to do a better job guarding against these tactics.

“How do we break this pattern? Here’s the methodology I always advise: In order to prevent attacks, you need to think like an attacker. Consider how the ‘bad guys’ will try to break into your account and/or network, and counteract those tactics,” Pickering said. “We, as an industry, get hung up on testing for compliances and following 'best practices,' while losing sight of the ever-present battle with which IT and security personnel are consistently embroiled.”

Layered Defense Needed

Like Anonymous, the SEA has made quite a name for itself in the hacker world. The hacktivist group has targeted many media sites, including the New York Times, the Washington Post, the Financial Times, the Associated Press, The Guardian, Twitter and Twing, over the past year.

Kevin O'Brien, enterprise solution architect at CloudLock, told us these attacks are one more example of why companies need to implement properly layered defense strategies. Again, the issue with the DNS compromise was that a single point of failure -- the domain record company hacked, in this case -- resulted in "real-world" damages.

"Any time a single point of failure exists, one should assume that it will be the target of concerted effort on the behalf of criminals who wish to exploit, destroy, or compromise an organization," O'Brien said. "The coming days will tell for certain, but it's probably safe to assume that the Gray Lady's staff had not considered whether or not their DNS host was properly auditing and securing their environment. In turn, the DNS host was probably not doing the same for their resellers."
 

Tell Us What You Think
Comment:

Name:



Salesforce.com is the market and technology leader in Software-as-a-Service. Its award-winning CRM solution helps 82,400 customers worldwide manage and share business information over the Internet. Experience CRM success. Click here for a FREE 30-day trial.


 Microsoft/Windows
1.   Windows 9 Preview Date: Sept. 30?
2.   Price Wars Hitting Laptop Market?
3.   Office 365 Tailored for Attorneys
4.   Plan Your Move from Windows 7 Now
5.   Microsoft Patch Tuesday Stars IE


advertisement
China Puts Microsoft Under the Lens
Official anti-monopoly probe launched.
Average Rating:
Plan Your Move from Windows 7 Now
But don't rush to deploy Windows 8.
Average Rating:
Dynamics CRM Online Extends Reach
Now available in 17 more countries.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
UPS Stores in 24 States Hit by Data Breach
Big Brown has been breached. UPS said that about 105,000 customer transactions at 51 of its UPS Store locations in 24 states could have been compromised between January and August.
 
Cost of Target Data Breach: $148 Million Plus Loss of Trust
The now infamous Target data breach is still costing the company -- and its shareholders -- plenty. In fact, the retailing giant forecast the December 2013 incident cost shareholders $148 million.
 
Aruba Networks Handles Black Hat with Aplomb
It's not an easy job. Aruba Networks' task throughout the Black Hat USA conference in Las Vegas this month was to ensure thousands of attendees could connect without malicious attacks.
 

Enterprise Hardware Spotlight
Acer's New Desktop Box Rides the Chrome OS Wave
Filling out its Chrome OS line, Acer is following the introduction of a larger Chromebook line earlier this month with a new tiny $180 desktop Chromebox and also a smaller Chromebook.
 
Three New Lenovo PCs Aimed at Business Users
Businesses everywhere want computing solutions that do more for less money, and Lenovo has unveiled three new desktop PCs that offer solid computing at a budget-minded price.
 
Aruba Networks Handles Black Hat with Aplomb
It's not an easy job. Aruba Networks' task throughout the Black Hat USA conference in Las Vegas this month was to ensure thousands of attendees could connect without malicious attacks.
 

Mobile Technology Spotlight
Google Glass Adds Voice Access to Phone Contacts
The latest update to Google Glass will let users access their top 20 phone contacts with voice commands alone. A user can then choose a phone call, Google hangouts, e-mail or text messaging.
 
Samsung, B&N Target Amazon with Nook Tablet
They've seen the enemy and it is Amazon. So Samsung and Barnes & Noble are teaming up to combat their common foe with a 7-inch tablet that blends Samsung’s tech, Nook’s content and e-reader platform.
 
Acer's New Desktop Box Rides the Chrome OS Wave
Filling out its Chrome OS line, Acer is following the introduction of a larger Chromebook line earlier this month with a new tiny $180 desktop Chromebox and also a smaller Chromebook.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | CRM Systems | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.