Site icon Auspreneur

Jemena improves API security

Chinese state-linked hackers have been engaged in a covert cyberespionage campaign since May, infiltrating email accounts at approximately 25 organizations, including US government accounts, according to Microsoft and US officials.

The US government swiftly detected the breach of federal government accounts and successfully prevented further intrusions, stated White House national security adviser Jake Sullivan during an interview with ABC’s “Good Morning America.”

An anonymous source familiar with the investigation revealed that the US State Department was among the government agencies affected.

Microsoft referred to the hacking group as Storm-0558 and disclosed that they used forged digital authentication tokens to gain unauthorized access to webmail accounts operating on the company’s Outlook service. The campaign began in May, as confirmed by Microsoft.

In response, Microsoft has directly contacted the targeted or compromised organizations, providing them with vital information to aid in investigation and response efforts. However, Microsoft did not disclose the specific organizations or governments impacted, emphasizing that the hacking group primarily targets entities in Western Europe.

White House National Security Council spokesman Adam Hodge acknowledged that the intrusion into Microsoft’s cloud security impacted “unclassified systems.” Immediate measures were taken to identify the source and vulnerability in the cloud service in coordination with Microsoft.

The State Department detected abnormal activity and promptly implemented measures to secure its systems, according to a department spokesperson.

In light of the cyberattack, the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) jointly issued an advisory to enhance monitoring of Microsoft Exchange Online environments, particularly emphasizing the importance of enabling both basic and premium logging and ensuring the logs are easily searchable.

CISA is reportedly collaborating with Microsoft to provide premium logs to customers at no cost.

Cybersecurity experts in the private sector have noted that this recent wave of hacking activity demonstrates the evolving capabilities of Chinese cyber groups. John Hultquist, chief analyst for Mandiant, stated that Chinese cyber espionage has advanced significantly from the crude tactics typically associated with such activities.

The Chinese embassy in London dismissed the accusations as “disinformation” and labeled the US government as “the world’s biggest hacking empire and global cyber thief.”

China consistently denies involvement in hacking operations, irrespective of the available evidence or context.

Gas pipeline and powerline operator Jemena has engaged Salt Security to secure APIs that are making calls for data from its modernised app estate. The utility is using Salt to discover APIs in its ecosystem, including shadow APIs, gather insights on data being carried across APIs to prevent accidental exposure of sensitive data and exfiltration, and to generate API specifications to streamline the process of documenting APIs and keeping inventory up to date. Jemena’s cyber security architecture lead Daniel Gordon said in a statement that the utility anticipates a fourfold increase API traffic “in the next year alone”, meaning a specific security solution was required. Salt was brought in under an application modernisation project that kicked off last year. According to a statement, “the company realised it needed to make API security a key component of the initiative” can you rewrite?ChatGPT

Jemena, a gas pipeline and powerline operator, has enlisted the services of Salt Security to enhance the security of its application programming interfaces (APIs) utilized in its modernized app estate.

Salt Security will assist Jemena in discovering APIs within its ecosystem, including identifying shadow APIs. It will also provide insights into the data flowing through the APIs to prevent inadvertent exposure of sensitive information and data exfiltration. Additionally, Salt will generate API specifications to streamline the documentation process and ensure an up-to-date inventory of APIs.

Daniel Gordon, Jemena’s cybersecurity architecture lead, emphasized the utility’s expectation of a significant increase in API traffic, estimating a fourfold rise within the next year alone. Consequently, Jemena recognized the need for a dedicated security solution.

Salt Security was engaged as part of an application modernization project initiated by Jemena last year. Recognizing the critical importance of API security, the company integrated it as a core component of the initiative.

Exit mobile version