This would hardly be a surprise. The NSA TAO was responsible for EternalBlue. And they have straight up stated that they hold on to some zero-day vulnerabilities for use. Hacking a "Microsoft Exchange Mail to attack and control the mail server of a major Chinese military enterprise" to collect SIGINT is rather exactly why the NSA exists. They should be assumed to be a state sponsored APT like any other.
Exploiting? Zero-day? Microsoft is a US' bitch and Windows has more backdoors than Linux has audio players. And China says it like those backdoors are unintentional vulnerabilities.
Even the EU which supposed to be US ally is moving away from Microsoft
Cybersecurity
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
- Be respectful. Everyone should feel welcome here.
- No bigotry - including racism, sexism, ableism, homophobia, transphobia, or xenophobia.
- No Ads / Spamming.
- No pornography.
Community Rules
- Idk, keep it semi-professional?
- Nothing illegal. We're all ethical here.
- Rules will be added/redefined as necessary.
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world