Connect with us

Technology

Microsoft describes how its leaders were spied on by Russian hackers

Published

on

Microsoft describes how its leaders were spied on by Russian hackers

The Russian state-sponsored hackers responsible for the SolarWinds attack launched a nation-state attack against Microsoft’s corporate systems, the company disclosed last week. Some members of Microsoft’s senior leadership team had their email accounts compromised by hackers, who may have been snooping on them for weeks or months.

Microsoft released a preliminary investigation of how the hackers circumvented its security measures, even though the software company’s original SEC report late on Friday had little details about how the attackers obtained access. It also serves as a warning that other firms have been targeted by the same hacking outfit, commonly known as Nobelium or by the weather-themed nickname “Midnight Blizzard,” which Microsoft uses to refer to them.

Initially, Nobelium used a password spray assault to gain access to Microsoft’s servers. Hackers employ a dictionary of possible passwords in this kind of brute force attack against accounts. Crucially, two-factor authentication was not activated on the compromised non-production test tenant account. In order to avoid discovery, Microsoft claims that Nobelium “tailored their password spray attacks to a limited number of accounts, using a low number of attempts.”

The group identified and compromised a historical test OAuth application that had elevated access to the Microsoft corporate environment by using the access they had gained from the previous attack. A popular open standard for token-based authentication is OAuth. It’s a widely used web feature that lets you log into apps and services without giving your password to a website. OAuth is used on websites that you might be able to get into with your Gmail account.

The group was able to produce more malicious OAuth apps and accounts thanks to this higher access, which also gave them access to Microsoft’s corporate network and, eventually, its Office 365 Exchange Online service, which gives users access to email inboxes.

“Midnight Blizzard leveraged these malicious OAuth applications to authenticate to Microsoft Exchange Online and target Microsoft corporate email accounts,” explains Microsoft’s security team.

Microsoft previously stated that it was “a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions.” The company has not disclosed the exact number of its corporate email accounts that were targeted and accessed.

Additionally, Microsoft has yet to provide a precise timeframe for the duration of the hackers’ eavesdropping on its top leadership group and other staff members. Although the first attack happened in late November 2023, Microsoft didn’t become aware of it until January 12th. This could indicate that for almost two months, the attackers surveilled Microsoft leaders.

The same group of hackers had earlier this week gotten access to Hewlett Packard Enterprise’s (HPE) “cloud-based email environment.” Although HPE did not identify the supplier, it did disclose that the event was “probably connected” to the “exfiltration of a restricted quantity of [Microsoft] SharePoint documents as early as May 2023.”

The Microsoft hack happened a few days after the business declared its intention to restructure its software security in response to significant attacks on the Azure cloud. This is Microsoft’s most recent cybersecurity incident. A Microsoft Exchange Server vulnerability allowed 30,000 companies’ email systems to be compromised in 2021, and Chinese hackers used a Microsoft cloud attack last year to access emails belonging to the US government. The same Nobelium group that carried out this embarrassing executive email hack previously targeted Microsoft in the massive SolarWinds attack almost three years ago.

The cybersecurity community will probably take issue with Microsoft’s revelation that a crucial test account was operating without two-factor authentication. Although there was no software vulnerability in Microsoft, the hackers were able to stealthily navigate Microsoft’s corporate network thanks to a series of incorrectly set up test setups. “In an interview with CNBC earlier this week, George Kurtz, the CEO of CrowdStrike, questioned how the compromise of the highest ranking officials at Microsoft occurred in a non-production test environment.” “I believe there will be much more information released on this,”

Kurtz was correct; additional information has surfaced, but some crucial elements remain unreported. Microsoft asserts that in order to properly defend against these threats, “mandatory Microsoft policy and workflows would ensure MFA and our active protections are enabled” if this identical non-production test environment were implemented today. Microsoft still has a lot of explaining to do, particularly if it wants its users to think that it is genuinely making improvements to the way it develops, tests, builds, and runs its services and software to better defend against security risks.

Technology

Google’s Isomorphic Labs Unveils AlphaFold 3, AI that Predicts Structures of Life’s Molecules

Published

on

The Google and DeepMind subsidiary Isomorphic Labs has created a new artificial intelligence model that is purportedly more accurate than existing methods at predicting the configurations and interactions of every molecule in life.

The AlphaFold 3 system, according to co-founder of DeepMind Demis Hassabis, “can predict the structures and interactions of nearly all of life’s molecules with state-of-the-art accuracy including proteins, DNA, and RNA.”

Protein interactions are essential for drug discovery and development. Examples of these interactions include those between enzymes that are essential for human metabolism and antibodies that fight infectious illnesses.

Published on May 8 in the academic journal Nature, DeepMind said that the findings might drastically cut down on the time and expense needed to create medicines that have the potential to save lives.

“We can design a molecule that will bind to a specific place on a protein, and we can predict how strongly it will bind,” Hassabis stated in a press release, utilizing these new powers.

Earlier, AlphaFold revolutionized research by making protein 3D structure prediction more straightforward. Nevertheless, prior to AlphaFold 3’s improvement, it was unable to forecast situations in which a protein bound with another molecule.

Despite being limited to non-commercial use, scientists are reportedly excited about its increased predictive power and ability to speed up the drug discovery process.

“AlphaFold 3 allows us to generate very precise structural predictions in a matter of seconds, according to a statement released by Isomorphic Labs on X.”

“This discovery opens up exciting possibilities for drug discovery, allowing us to rationally develop therapeutics against targets that were previously difficult or deemed intractable to modulate,” the blog post continued.

The AlphaFold Server Login Process

The AlphaFold Server, a recently released research tool, will be available to scientists for free, according to a statement made by Google DeepMind and Isomorphic Labs.

Isomorphic Labs is apparently collaborating with pharmaceutical companies to use the potential of AlphaFold 3 in drug design. The goal is to tackle practical drug design issues and ultimately create novel, game-changing medicines for patients.

Since 2021, a database containing more than 200 million protein structures has made AlphaFold’s predictions freely available to non-commercial researchers. In academic works, this resource has been mentioned thousands of times.

According to DeepMind, researchers may now conduct experiments with just a few clicks thanks to the new server’s simplified workflow.

Using a FASTA file, AlphaFold Server’s web interface will enable data entry for a variety of biological molecule types. After processing the task, the AI model displays a 3D overview of the structure.

Continue Reading

Technology

Phone.com Launches AI-Connect, a Cutting-Edge Conversational AI Service

Published

on

AI-Connect, a revolutionary conversational speech artificial intelligence (AI) service, was unveiled by Phone.com today. AI-Connect, the newest development in Phone.com’s commercial phone system, offers callers and businesses a smooth and effective contact experience.

AI-Connect is specifically designed to handle inbound leads and schedule appointments without the clumsiness of cookie-cutter call routing or the expense of a contact center. This is ideal for small and micro businesses that need to take advantage of every opportunity to convert interest into sales but lack the luxury of an administrative team or a call center to handle the influx of prospects or sales calls.

AI-Connect can effectively manage duties like call routing, schedule management, and FAQ responding since it is built to engage in genuine, free-flowing conversations with callers. Modern automatic voice recognition (ASR), large language model (LLM), text-to-speech (TTS), natural language understanding (NLU), and natural language processing (NLP) technologies are used to enable this capacity.

The real differentiator with AI-Connect is its capacity to provide goal-oriented, conversational communication. Excellent intent recognition is provided by the company’s creative use of LLM in conjunction with NLU/NLP hybrid infrastructure. Notable is also how the new service leverages machine learning to deliver customized suggestions and detailed call metrics for every engagement.

Phone.com CEO and Co-Founder Ari Rabban stated, “AI-Connect is much more than just a service or new iteration of AI-enabled CX; it’s a strategic game-changer that strips away the burden of expensive, complicated technology designed for small businesses.” “AI-Connect, a component of our UCaaS platform, dismantles conventional barriers and gives companies of all sizes access to a realm of efficiency and expertise that would normally require significant time and investment.”

A professional voice greets customers and provides them with a number of easy options when they initiate a call to an AI-Connect script. AI-Connect guarantees that Phone.com customers maximize every engagement, regardless of their availability to answer, from easily arranging, rescheduling, or canceling appointments to smoothly connecting with a specific contact or department.

AI-Connect effectively filters out spam and other undesirable calls by utilizing sophisticated call screening capabilities, saving both business owners and callers important time.

The discussion between callers and AI-Connect is facilitated by sophisticated conversational design, which also optimizes call flow and delivers real-time responses that are most effective. Businesses may easily modify and implement AI-Connect to meet their specific needs thanks to the intuitive user interface (UI).

“We look forward to embarking on the next chapter of communications with great anticipation as innovation is in our DNA,” said Alon Cohen, the acclaimed Chief Technology Officer of Phone.com, whose engineering prowess produced the first VoIP call ever. The FCC’s Pulver Order, which removed certain IP-based communication services from conventional regulatory restrictions, ushered in a new age and was implemented 20 years ago. With AI-assisted interactions, “we are now in a position to investigate their transformational potential. Our commitment to transforming communication is reaffirmed as we embark on a journey towards a future characterized by intelligent solutions.”

Phone.com is celebrating 15 years of consecutive year-over-year growth, driven by a strong clientele that includes more than 50,000 enterprises and an impressive increase in market share. Supported by an unwavering dedication to providing state-of-the-art services and technology at reasonable costs, the company’s approach works well for enterprises of all sizes, accelerating its trajectory of steady expansion.

Continue Reading

Technology

Biosense Webster Unveils AI-Driven Heart Mapping Technology

Published

on

Today, Biosense Webster, a division of Johnson & Johnson MedTech, announced the release of the most recent iteration of its Carto 3 cardiac mapping system.

Heart mapping in three dimensions is available for cardiac ablation procedures with Carto 3 Version 8. It is integrated by Biosense Webster into technology such as the FDA-reviewed Varipulse pulsed field ablation (PFA) system.

Carto Elevate and CartoSound FAM are two new modules that Biosense Webster added to the software. These modules were created by the company to be accurate, efficient, and repeatable when used in catheter ablation procedures for arrhythmias such as AFib.

Biosense Webster’s CartoSound FAM encompasses the first application of artificial intelligence in intracardiac ultrasound. In addition to saving time, the algorithm, according to the company, provides a highly accurate map by automatically generating the left atrial anatomy prior to the catheter being inserted into the left atrium. Through the use of deep learning technology, the module produces 3D shells automatically.

Incorporating multipolar capabilities with the Optrell mapping catheter is one of the new features of the Carto Elevate module. By doing so, far-field potentials are greatly reduced and a more precise activation map for localized unipolar signals is produced. The identification of crucial areas of interest is done effectively and consistently with Elevate’s complex signals identification. An improved Confidense module generates optimal maps, and pattern acquisition automatically monitors arrhythmia burden prior to and following ablation.

Jasmina Brooks, president of Biosense Webster, stated, “We are happy to announce this new version of our Carto 3 system, which reflects our continued focus on harnessing the latest science and technology to advance tools for electrophysiologists to treat cardiac arrhythmias.” For over a decade, the Carto 3 system has served as the mainstay of catheter ablation procedures, assisting electrophysiologists in their decision-making regarding patient care. With the use of ultrasound technology, better substrate characterization, and improved signal analysis, this new version improves the mapping and ablation experience of Carto 3.

Continue Reading

Trending

error: Content is protected !!