Reuters - A Russian group of hackers who hit diplomatic targets in the United States and elsewhere allegedly used two unknown software vulnerabilities to violate its targets, according to the security company investigating the matter.
Η FireEye, a prominent US security firm, said the group took holes in Adobe Systems Inc.'s Flash software, but also in Microsoft's most widely-used Windows operating system.
This group appears to have been behind the serious violation of the State Department's systems. The same hackers are also believed to have violated White House systems that contained unclassified but sensitive information such as the President's travel program.
FireEye is trying to help the government by scrutinizing these attacks, but said he can not comment further on the issue, or whether they were themselves hackers that infiltrated the White House, because this information has been classified as confidential.
FireEye said Adobe had released an update on the vulnerability that hackers used on Tuesday to protect those using its applications. The problem of Microsoft itself is less dangerous, as the security company says. However, a Microsoft spokesman said the company was preparing a patch.
In October, FireEye said the Russian APT28 team from 2007, targeting US defense services, NATO alliance offices, as well as government officials in Georgia and other countries of particular interest to the Kremlin.
A few days before the report, security company Trend Micro Inc described an attack it called a "Pawn Storm" against State Department computers, Russian dissidents, NATO and other Eastern European countries. The Pawn Storm attack and the APT28 team used the same tools to hit their targets, and so the information security researchers concluded that they were the same hackers.
On Thursday, Trend Micro said that the hackers of the Pawn Storm attack had increased activity on bloggers who had interviewed President Barack Obama. Investigators also said the group "probably" had stolen credentials from a military correspondent in a major US newspaper.
Please be aware that the security gaps used by the APT28 team were new, so these hackers have a very high level of expertise.
Dimitris hates Mondays...

