• Home
  • Agric
  • Sci & Tech
  • Health
  • Environment
  • Hausa News
  • More
    • Business/Banking & Finance
    • Politics/Elections
    • Entertainments & Sports
    • International
    • Investigation
    • Law & Human Rights
    • Africa
    • ACCOUNTABILITY/CORRUPTION
    • Hassan Gimba
    • Column
    • Prof. Jibrin Ibrahim
    • Prof. M.K. Othman
    • Defense/Security
    • Education
    • Energy/Electricity
    • Entertainment/Arts & Sports
    • Society and Lifestyle
    • Food & Agriculture
    • Health & Healthy Living
    • International News
    • Interviews
    • Investigation/Fact-Check
    • Judiciary/Legislature/Law & Human Rights
    • Oil & Gas/Mineral Resources
    • Press Freedom/Media/PR/Journalism
    • General News
    • Presidency
  • About Us
    • Contact Us
    • Board Of Advisory
    • Privacy Policy
    • Ethics Policy
    • Teamwork And Collaboration Policy
    • Fact-Checking Policy
    • Advertising
  • Media OutReach Newswire
    • Wire News
  • The Stories
Facebook Twitter Instagram
Trending
  • Expert seeks stronger measures against hospital-acquired infections
  • Leventis foundation, NYSC to reward top young agripreneurs
  • Edo govt, IFAD LIFE-ND train 630 youths in agribusiness
  • NUPRC seeks Bank of America funding for Nigeria’s upstream sector
  • Senate to cut $2bn rice import bill, establish national council
  • ASUU seeks Sen. Wamakko’s intervention to end lingering dispute with FG
  • Kwara launches free cancer screening for residents
  • Nigeria’s environment at risk from poor waste management, EPHPAN warns
Facebook Twitter Instagram YouTube
AsheNewsAsheNews
  • Home
  • Agric

    Leventis foundation, NYSC to reward top young agripreneurs

    October 29, 2025

    Edo govt, IFAD LIFE-ND train 630 youths in agribusiness

    October 29, 2025

    Senate to cut $2bn rice import bill, establish national council

    October 29, 2025

    Gov Bago unveils plan to expand sugar, crop production

    October 28, 2025

    ADC faults FG over alleged manipulation of food prices

    October 28, 2025
  • Sci & Tech

    NIHOTOUR partners with circuits to digitize hospitality training

    October 28, 2025

    UNESCO trains Cross River communities on biodiversity conservation

    October 28, 2025

    NaaS Innovator Graphiant, Zenture partner to deliver unified, AI-ready enterprise networking

    October 28, 2025

    Nigeria, UNESCO train Oban communities on biodiversity businesses

    October 27, 2025

    Ntel sets sights on Nigeria’s next telecom revolution

    October 27, 2025
  • Health

    Kwara launches free cancer screening for residents

    October 28, 2025

    NNRA told to step up monitoring of lonizing radiation in Nigeria

    October 28, 2025

    NDLEA uncovers drugs hidden in frozen snails, bulbs, clothes bound for US, UK, DRC

    October 28, 2025

    NVMA president: 65% of human diseases in Nigeria are zoonotic

    October 28, 2025

    SCI urges stronger media focus on child rights in Nigeria

    October 28, 2025
  • Environment

    Nigeria’s environment at risk from poor waste management, EPHPAN warns

    October 28, 2025

    Nigeria launches green women platform to drive climate solutions

    October 28, 2025

    Nigeria targets sustainable, mercury-free mining in 4 states

    October 28, 2025

    Nasarawa lawmakers approve climate action policy

    October 28, 2025

    LASEMA confirms fatality in Lagos building collapse

    October 27, 2025
  • Hausa News

    Anti-quackery task force seals 4 fake hospitals in Rivers

    August 29, 2025

    [BIDIYO] Yadda na lashe gasa ta duniya a fannin Ingilishi – Rukayya ‘yar shekara 17

    August 6, 2025

    A Saka Baki, A Sasanta Saɓani Tsakanin ‘Yanjarida Da Liman, Daga Muhammad Sajo

    May 21, 2025

    Dan majalisa ya raba kayan miliyoyi a Funtuwa da Dandume

    March 18, 2025

    [VIDIYO] Fassarar mafalki akan aikin Hajji

    January 6, 2025
  • More
    1. Business/Banking & Finance
    2. Politics/Elections
    3. Entertainments & Sports
    4. International
    5. Investigation
    6. Law & Human Rights
    7. Africa
    8. ACCOUNTABILITY/CORRUPTION
    9. Hassan Gimba
    10. Column
    11. Prof. Jibrin Ibrahim
    12. Prof. M.K. Othman
    13. Defense/Security
    14. Education
    15. Energy/Electricity
    16. Entertainment/Arts & Sports
    17. Society and Lifestyle
    18. Food & Agriculture
    19. Health & Healthy Living
    20. International News
    21. Interviews
    22. Investigation/Fact-Check
    23. Judiciary/Legislature/Law & Human Rights
    24. Oil & Gas/Mineral Resources
    25. Press Freedom/Media/PR/Journalism
    26. General News
    27. Presidency
    Featured
    Recent

    Expert seeks stronger measures against hospital-acquired infections

    October 29, 2025

    Leventis foundation, NYSC to reward top young agripreneurs

    October 29, 2025

    Edo govt, IFAD LIFE-ND train 630 youths in agribusiness

    October 29, 2025
  • About Us
    1. Contact Us
    2. Board Of Advisory
    3. Privacy Policy
    4. Ethics Policy
    5. Teamwork And Collaboration Policy
    6. Fact-Checking Policy
    7. Advertising
    Featured
    Recent

    Expert seeks stronger measures against hospital-acquired infections

    October 29, 2025

    Leventis foundation, NYSC to reward top young agripreneurs

    October 29, 2025

    Edo govt, IFAD LIFE-ND train 630 youths in agribusiness

    October 29, 2025
  • Media OutReach Newswire
    • Wire News
  • The Stories
AsheNewsAsheNews
Home»General News»Alleged Russian hacks of Microsoft Service Providers highlight cybersecurity deficiencies
General News

Alleged Russian hacks of Microsoft Service Providers highlight cybersecurity deficiencies

Abdallah el-KurebeBy Abdallah el-KurebeNovember 7, 2021No Comments6 Mins Read
Cubed background in different sizes and blue colors aligning to a row of glowing information security icons surrounding the word cybersecurity 3D illustration
Share
Facebook Twitter LinkedIn Pinterest Email

By VOA

Cybersecurity experts say Microsoft’s recent disclosure that alleged Russian hackers successfully attacked several IT service providers this year, is a sign that many U.S. IT companies have underinvested in security measures needed to protect themselves and their customers from intrusions.

But a U.S.-based association of IT professionals says the industry’s efforts to combat foreign hacking attacks are hampered by their customers not practicing good cyber habits and by the federal government not doing enough to punish and deter the hackers.

In an October 24 blog post, Microsoft said a Russian nation-state hacking group that it calls Nobelium spent three months attacking companies that resell, customize and manage Microsoft cloud services and other digital technologies for public and private customers. Microsoft said it informed 609 of those companies, known as managed service providers, or MSPs, that they had been attacked 22,868 times by Nobelium from July 1 to October 19 this year.

‘Well-known techniques’

As of its October 24 blog post, Microsoft said it determined that “as many as 14” of the resellers and service providers had been compromised in the Nobelium attacks, which it said involved the use of “well-known techniques, like password spray and phishing, to steal legitimate credentials and gain privileged access.”

Nobelium is the same group that Microsoft said was responsible for last year’s cyberattack on U.S. software company SolarWinds. That attack involved inserting malicious code into SolarWinds’ IT performance monitoring system, Orion, and gave the hackers access to the networks of thousands of U.S. public and private organizations that use Orion to manage their IT resources.

The White House said in April that it believed the perpetrators of the SolarWinds hack were part of the Russian foreign intelligence service, or SVR.

In an October 29 statement published by Russian network RBC TV, Russia’s foreign ministry dismissed as “groundless” Microsoft’s accusation that SVR was behind the recent cyberattacks on IT companies. It also said Microsoft should have shared data on the attacks with the Russian government’s National Coordination Center for Computer Incidents to aid a “professional and effective dialogue to … identify those involved.”

VOA asked Microsoft whether the company had communicated with Moscow regarding the latest hacking incidents, but Microsoft declined to comment.

It also has not disclosed the names or locations of any of the targeted or compromised IT companies.

Charles Weaver, chief executive of the U.S.-based International Association of Cloud and Managed Service Providers, also known as MSPAlliance, told VOA that he had not heard of any of his organization’s members being affected by the latest Nobelium attacks.

MSPAlliance describes itself as the world’s largest industry group for people who manage hardware, software and cloud computing services for customers. It says it has more than 30,000 members worldwide, about two-thirds of them based in North America.

Insufficient attention

The apparently successful cyberattacks on Microsoft-linked IT companies are a sign that U.S. MSPs are not putting enough priority on cybersecurity, said Jake Williams, a chief technology officer at U.S. cybersecurity company BreachQuest and a former U.S. National Security Agency elite hacking team member.

“The profit margins for MSPs are often razor-thin, and in the majority of cases, they compete purely on cost,” Williams told VOA in an interview. “Any work they do that doesn’t directly translate to additional revenue is generally not happening.”

One cybersecurity practice that more MSPs should adopt is the sharing of information with U.S. authorities about hacking incidents, said James Curtis, a cybersecurity program director at Webster University in Missouri, in a conversation with VOA’s Russian Service.

Curtis, a retired U.S. Air Force cyber officer and a former IT industry executive, said MSPs do not like to admit they have been hacked.

“They don’t want to share that their users’ information has been stolen, because it may hurt their bottom line and may hurt their stock prices, and so they try to handle that internally,” he said.

“The MSP community is not perfect,” Weaver said. “Our members face a lot of cyberattacks and their job is to protect their customers against these things. For 21 years, MSPAlliance has strived to promote best practices for our global community, and we will continue to incrementally improve as fast and as often as we can.”

But Weaver said criticism of MSPs for not devoting enough attention to cybersecurity is misplaced.

Customer practices

“MSPs have been urging their customers to make easy and inexpensive fixes such as adopting multifactor authentication to back up their data to the cloud,” Weaver said. “But I personally have witnessed a lot of nonconformity amongst the customers. They have to be the ones that ultimately pay for and allow MSPs to deploy those fixes.”

The Biden administration also has used a variety of tools this year to try to protect U.S. targets from Russian and other foreign hackers. In May, President Joe Biden issued an executive order for U.S. authorities to tighten cybersecurity contractual requirements for IT companies that work with the federal government. The order said the companies should be required to share more information with federal agencies about cyber incidents impacting the IT services provided to those agencies.

In an earlier action in April, the Biden administration sanctioned six Russian technology companies for providing support to what it called malicious cyber activities of Russia’s intelligence services.

Senior U.S. officials also have used diplomacy to try to expand international participation in a Counter-Ransomware Initiative (CRI). A U.S. National Security Council statement issued Wednesday said deputy national security adviser Anne Neuberger briefed representatives of 35 countries Tuesday on the outcome of last month’s first CRI meeting of experts from law enforcement, cybersecurity, financial regulators and foreign affairs ministries.

Chris Morgan, an intelligence analyst at Britain-based cybersecurity company Digital Shadows, told VOA the stronger cybersecurity practices mandated by the U.S. government for federal contractors will not necessarily be voluntarily adopted by IT companies working in the private sector. One such mandated practice is for federal contractors to adopt a “zero-trust” security model, in which users who log in to a network are not automatically trusted to do whatever they like within that network but must instead undergo continual authentication.

Larger government role

“Implementing zero-trust is a real change in the way that your network is managed and comes with significant costs. I think that’s the reason why a lot of companies are quite hesitant to do so,” Morgan said. “I think a lot of people would like the U.S. government to take a more active role in combating cybercrime [through promoting measures like zero-trust].”

Weaver, of MSPAlliance said applying federal cybersecurity regulations to the entire private sector is not a good idea because different industries, such as banking, health care and energy, have different IT needs.

He also said the U.S. government could effectively curb ransomware attacks by doing more to hold the perpetrators accountable.

“Cyberattacks are a big business, yet the hackers are in countries beyond the reach of our law enforcement,” Weaver said. “So you have a business model that has no disincentive to stop. And all we have are the IT guardians against those attacks. I just don’t think that putting regulations on the guardians is going to solve this.”

By VOA

Cyberattacks Cybersecurity Microsoft Service Providers MSPAlliance Ransomware
Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Abdallah el-Kurebe
  • Website
  • Facebook
  • Twitter
  • LinkedIn

Related Posts

Southern group alleges persecution of northern Muslim leaders under Tinubu administration

October 27, 2025

Experts, advocates demand inclusive infrastructure at Niger disability summit

October 27, 2025

The deadly lure of spilled fuel: Niger’s endless cycle of tanker tragedies

October 27, 2025

Leave A Reply Cancel Reply

Expert seeks stronger measures against hospital-acquired infections

October 29, 2025

Leventis foundation, NYSC to reward top young agripreneurs

October 29, 2025

Edo govt, IFAD LIFE-ND train 630 youths in agribusiness

October 29, 2025

NUPRC seeks Bank of America funding for Nigeria’s upstream sector

October 29, 2025
About Us
About Us

ASHENEWS (AsheNewsDaily.com), published by PenPlus Online Media Publishers, is an independent online newspaper. We report development news, especially on Agriculture, Science, Health and Environment as they affect the under-reported rural and urban poor.

We also conduct investigations, especially in the areas of ASHE, as well as other general interests, including corruption, human rights, illicit financial flows, and politics.

Contact Info:
  • 1st floor, Dogon Daji House, No. 5, Maiduguri Road, Sokoto
  • +234(0)7031140009
  • ashenewsdaily@gmail.com
Facebook Twitter Instagram Pinterest
© 2025 All Rights Reserved. ASHENEWS Daily Designed & Managed By DeedsTech

Type above and press Enter to search. Press Esc to cancel.