Day: June 18, 2023

Microsoft Says Early June Disruptions to Outlook, Cloud Platform, Were Cyberattacks 

In early June, sporadic but serious service disruptions plagued Microsoft’s flagship office suite — including the Outlook email and OneDrive file-sharing apps — and cloud computing platform. A shadowy hacktivist group claimed responsibility, saying it flooded the sites with junk traffic in distributed denial-of-service attacks.

Initially reticent to name the cause, Microsoft has now disclosed that DDoS attacks by the murky upstart were indeed to blame.

But the software giant has offered few details — and did not immediately comment on how many customers were affected and whether the impact was global. A spokeswoman confirmed that the group that calls itself Anonymous Sudan was behind the attacks. It claimed responsibility on its Telegram social media channel at the time. Some security researchers believe the group to be Russian.

Microsoft’s explanation in a blog post Friday evening followed a request by The Associated Press two days earlier. Slim on details, the post said the attacks “temporarily impacted availability” of some services. It said the attackers were focused on “disruption and publicity” and likely used rented cloud infrastructure and virtual private networks to bombard Microsoft servers from so-called botnets of zombie computers around the globe.

Microsoft said there was no evidence any customer data was accessed or compromised.

While DDoS attacks are mainly a nuisance — making websites unreachable without penetrating them — security experts say they can disrupt the work of millions if they successfully interrupt the services of a software service giant like Microsoft on which so much global commerce depends.

It’s not clear if that’s what happened here.

“We really have no way to measure the impact if Microsoft doesn’t provide that info,” said Jake Williams, a prominent cybersecurity researcher and a former National Security Agency offensive hacker. Williams said he was not aware of Outlook previously being attacked at this scale.

“We know some resources were inaccessible for some, but not others. This often happens with DDoS of globally distributed systems,” Williams added. He said Microsoft’s apparent unwillingness to provide an objective measure of customer impact “probably speaks to the magnitude.”

Microsoft dubbed the attackers Storm-1359, using a designator it assigns to groups whose affiliation it has not yet established. Cybersecurity sleuthing tends to take time — and even then can be a challenge if the adversary is skilled.

Pro-Russian hacking groups including Killnet — which the cybersecurity firm Mandiant says is Kremlin-affiliated — have been bombarding government and other websites of Ukraine’s allies with DDoS attacks. In October, some U.S. airport sites were hit. Analyst Alexander Leslie of the cybersecurity firm Recorded Future said it’s unlikely Anonymous Sudan is located as it claims in Sudan, an African country. The group works closely with Killnet and other pro-Kremlin groups to spread pro-Russian propaganda and disinformation, he said.

Edward Amoroso, NYU professor and CEO of TAG Cyber, said the Microsoft incident highlights how DDoS attacks remain “a significant risk that we all just agree to avoid talking about. It’s not controversial to call this an unsolved problem.”

He said Microsoft’s difficulties fending of this particular attack suggest “a single point of failure.” The best defense against these attacks is to distribute a service massively, on a content distribution network for example.

Indeed, the techniques the attackers used are not old, said U.K. security researcher Kevin Beaumont. “One dates back to 2009,” he said.

Serious impacts from the Microsoft 365 office suite interruptions were reported on Monday June 5, peaking at 18,000 outage and problem reports on the tracker Downdetector shortly after 11 a.m. Eastern time.

On Twitter that day, Microsoft said Outlook, Microsoft Teams, SharePoint Online and OneDrive for Business were affected.

Attacks continued through the week, with Microsoft confirming on June 9 that its Azure cloud computing platform had been affected.

On June 8, the computer security news site BleepingComputer.com reported that cloud-based OneDrive file-hosting was down globally for a time.

Microsoft said at the time that desktop OneDrive clients were not affected, BleepingComputer reported.

more

Secret Washington Garden Has Vital Government Mission

Nestled among the bustling city streets of Washington is a hidden oasis that many Americans don’t know exists. Congress established the U.S. National Arboretum in 1927. Vital scientific research is under way at the sprawling 183-hectare compound. VOA’s Dora Mekouar reports on the arboretum’s critical government mission. Camera: Adam Greenbaum

more

Pastors Find Role Ministering to Young Men Swept up in El Salvador’s Crackdown on Gangs

The smell of pineapple bread fills the kitchen of “Vida Libre,” or “free life,” a gang rehabilitation program founded in El Salvador by American pastor Kenton Moody in 2021.

The trust that Moody puts in former gang members is not widely shared. Thousands of lives have been destroyed in this Central American country after decades of gang violence.

Over the past year, President Nayib Bukele’s security forces have cracked down harshly on gangs, arresting more than 68,000 people suspected of criminal involvement, though human rights groups say innocent people are also being detained.

Ministries like Moody’s are caught in the middle. Dozens of men who were part of evangelical rehabilitation ministries were also arrested and taken back to prison. Of the 38 members of Vida Libre, ten have been detained by the government.

Inside the Vida Libre complex, in the impoverished city of Santa Ana, Moody frequently hugs the young men under his care and assigns them chores.

On a recent day, Angel and Kevin sprinkled sugar over pastries in the bakery. Salvador replaced light bulbs in the barnyard. Moody asked that they be identified by their first names for their safety.

Andy, who crafts wooden key chains to sell, said a gang recruited him when he was 12. The 29-year-old joined Moody’s program two years ago after almost a decade in prison.

“Maybe humanity sees me as someone bad, but I hope that with my attitudes changing day by day, I can prove that I’m different,” he said.

The first of the big gangs were born far from El Salvador.

To flee the country’s civil war, half a million Salvadorans migrated to the United States in the 1980s. The majority settled in Los Angeles and there, after joining Mexican criminal groups, the Mara Salvatrucha 13 (MS-13) and Barrio 18 gangs were formed.

In the 1990s, the U.S. deported 4,000 gang members to El Salvador. The government estimates the current number of gang members is as high as 76,000.

After arriving in El Salvador, MS-13 took control of over roughly half the territory and Barrio 18 most of the rest. A few spots were considered neutral.

Many Salvadorans were forced to internalize unwritten rules, such as avoiding enemy neighborhoods, dressing according to gang standards and paying extortion demands to survive.

Last year, after a surge in gang violence, Bukele issued an emergency decree that suspended certain civil liberties, including access to a lawyer and the right to be informed of the reason for an arrest.

About 5,000 people were released after the government failed to link them to criminal groups, according to official records.

Moody founded Vida Libre after visiting a juvenile prison where gang members from a nearby community were incarcerated for burying a woman alive.

Fearing that they might return to gang life upon their release, he wondered: How can I truly help?

“A church is the basis for supporting people to get ahead,” he said.

His evangelical church, “La Puerta Abierta,” which means “open door,” is a cornerstone for social projects funded mostly by U.S. donors.

Vida Libre, one of the church’s programs, takes in minors who are nearing the end of their prison sentence. Its goal is to provide an adequate transition to society, said Allan Espinoza, who leads the project.

The stigma of prison makes it difficult for ex-convicts to resume their studies or find employment. Vida Libre offers workshops in agriculture, carpentry, automotive painting and baking.

Participants arise at 5 a.m. to attend a morning service, and they read the Bible daily. Breaking the rules leads to expulsion and rehabilitation takes time, Espinoza said. Some tell him they want to leave, but he asks them to be patient.

Others knock on his door to talk and, once in his office, they just cry.

Not all evangelical churches in El Salvador open their doors to gang members, but in most marginalized communities there are pastors willing to take the risk.

“Within the evangelical tradition, the worst sinner provides the Holy Spirit with the biggest opportunity to demonstrate the power of the Gospel and Jesus to transform people,” said Robert Brenneman, professor of criminal justice and sociology at Goshen College in Indiana.

He spent years in Central America studying gang youth who wanted a stable, nonviolent lifestyle.

Evangelical-Pentecostal congregations offer resources for transformation — and expect converts to stay away from crime, alcohol and drugs.

“These organizations address what they believe to be the root causes of gang affiliation and participation: poverty, weak schools and unemployment,” Brenneman said.

In the last two decades, three Salvadoran presidents have imposed strict measures to fight gangs. The two prior to Bukele failed in the long term.

Brenneman said, “The crisis is larger than the gangs … Salvadoran leaders have been able to scapegoat the gangs and direct attention away from the inequality that drives so much of the violence.”

While walking through an empty room behind Eben-Ezer Church in San Salvador, the Rev. Nelson Moz speaks with sadness about a man named Raúl, an ex-gang member who came under Moz’s wing in 2012.

Raúl and more than 40 men from Moz’s ministry are now back in jail.

According to the pastor, Raúl converted to Christianity in prison. The pastor placed a mattress in his office and offered temporary refuge for Raúl after his initial release. They shared lunch and long conversations there.

“That’s how I got to understand,” Moz said. “Imprisonment might be necessary to take out of circulation a person who is causing harm to society, but there’s a background to it.”

Gang members understood this. To those in need, they offered food, clothing and protection. For thousands of Salvadorans who lacked homes, the gang became their family.

The beds are still made in the empty rooms of Eben-Ezer Church.

Some new mattresses are wrapped in plastic. Before the detention of Raúl and other ex-gang members in his program, Moz was planning to expand. “True change can happen,” he said.

Moz and Moody do what they can to support families whose members have been recently imprisoned by the government. Moody builds wooden homes for single mothers and provides free school for children. Moz looks for people willing to take in orphans.

“Young people can change the course of the family, help the country’s poverty if they have education and work,” Moody said.

Rooting out gangs will take years, he thinks. The weeds have been cut, but as long as the roots remain hidden, the breeding ground — the marginalization — will also subsist.

more