Washington Post's email system hacked, journalists' accounts compromised
《华盛顿邮报》部分记者的电子邮件账户遭遇网络攻击,疑似由外国政府实施。此次攻击针对报道国家安全、经济政策及中国的记者。过去中国黑客曾利用微软Exchange漏洞进行类似攻击。目前事件详情尚未公开。 2025-6-16 15:15:27 Author: www.bleepingcomputer.com(查看原文) 阅读量:14 收藏

Washington Post's email system hacked, journalists' accounts compromised

Email accounts of several Washington Post journalists were compromised in a cyberattack believed to have been carried out by a foreign government.

The incident was discovered on Thursday evening and the publication started an investigation. On Sunday, June 15, an internal memo was sent to employees, informing them of a “possible targeted unauthorized intrusion into their email system.”

According to The Wall Street Journal, the memo was signed by Executive Editor Matt Murray and informed that Microsoft accounts of a limited number of journalists were affected.

Owned by Amazon founder Jeff Bezos, The Washington Post is one of the most influential newspaper publications in the United States.

Internal sources told The Wall Street Journal that the attack targeted journalists writing on national security and economic policy topics, as well as some who write about China.

Advanced persistent threats (APTs), or state-sponsored actors, often target email systems like Microsoft Exchange. Two years ago, Chinese hackers leveraged insecure Exchange endpoints to breach email accounts of two dozen government agencies globally, accessing extremely sensitive and confidential data.

But Chinese threat groups have a long history of exploiting Exchange vulnerabilities in highly organized campaigns. They targeted U.S. government agencies in 2020, and multiple NATO members in 2021.

Last year, Microsoft warned that hackers were exploiting a critical privilege elevation bug in Exchange as a zero-day to perform NTLM relay attacks.

ESET cybersecurity company also discovered in 2021 multiple Chinese threat groups, including APT27, Bronze Butler, and Calypso, exploiting zero-day vulnerabilities in Microsoft Exchange.

Washington Post has not shared publicly any details about the attack.

Tines Needle

Why IT teams are ditching manual patch management

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work -- no complex scripts required.


文章来源: https://www.bleepingcomputer.com/news/security/washington-posts-email-system-hacked-journalists-accounts-compromised/
如有侵权请联系:admin#unsafe.sh