<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/microsoft-sql-server-mssql"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Microsoft-sql-server-mssql ]]></title>
                <link>https://www.itpro.com/uk/tag/microsoft-sql-server</link>
        <description><![CDATA[ All the latest microsoft-sql-server-mssql content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Wed, 12 Jul 2023 11:54:08 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Microsoft SQL password-guessing attacks rising as hackers pivot from OneNote vectors ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/microsoft-sql-password-guessing-attacks-rising-as-hackers-picot-from-onenote-vectors</link>
                                                                            <description>
                            <![CDATA[ Database admins are advised to enforce better controls as attacks ending in ransomware are being observed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Umthpss9ruTMtDiWXfTLT9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U3XRG9ZZjSHHxMUXhHdqk7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Jul 2023 11:54:08 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jul 2023 13:49:44 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Rory Bathgate) ]]></author>                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U3XRG9ZZjSHHxMUXhHdqk7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft SQL: The Microsoft logo against a white background out of focus, with the silhouette of a hand holding a padlock to the left of frame in focus.]]></media:description>                                                            <media:text><![CDATA[Microsoft SQL: The Microsoft logo against a white background out of focus, with the silhouette of a hand holding a padlock to the left of frame in focus.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft SQL: The Microsoft logo against a white background out of focus, with the silhouette of a hand holding a padlock to the left of frame in focus.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U3XRG9ZZjSHHxMUXhHdqk7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Malware attacks using Microsoft SQL (MSSQL) Server as an intrusion vector have risen sharply in the last six months, as experts report hackers moving away from blocked methods.</p><p>Researchers at cyber security firm ESET revealed the absolute count of MSSQL attacks increased by 84% between H2 2022 and H1 2023. </p><p>The rise in attacks utilizing the vector was linked to Microsoft’s landmark move to block Virtual Basic for Applications (VBA) macros in Office documents by default last year.</p><p>Cyber security professionals had been calling for stricter default controls for VBA macros for years before Microsoft finally implemented the changes.</p><p>Exploiting VBA macros in Office documents was historically one of the most popular methods of embedding malware in seemingly innocuous files which were downloaded as part of <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> campaigns.</p><p>Shortly after this avenue of attack was blocked off, researchers recorded a clear rise in the number of attacks using OneNote as a vector instead. </p><p>Cyber criminals behind malware such as <a href="https://www.itpro.com/security/hacking/361340/what-is-emotet"><u>Emotet</u></a> exploited .one files to trick users into running malicious scripts, moving on from <a href="https://www.itpro.com/security/cyber-security/370253/new-emotet-socially-engineers-evade-detection"><u>their own abuse of VBA macros</u></a>.</p><p>In its <a href="https://www.welivesecurity.com/wp-content/uploads/2023/07/eset_threat_report_h12023.pdf" target="_blank">report</a>, ESET said Microsoft’s blocking of VBA macros and its efforts to shore up the security of OneNote means that “cyber criminals may be looking at MSSQL and other intrusion vectors more closely” for the future.</p><p>MSSQL is a widely-used solution for regional database management, and when exposed to the internet can be a tempting target for hackers. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="XoGp9XGktCfhhm5KZbiWzT" name="The Board's Evolving Perceptions of Cyber Risk (1).jpg" caption="" alt="Whitepaper from Mimecast about cyber risk as business risk" src="https://cdn.mos.cms.futurecdn.net/XoGp9XGktCfhhm5KZbiWzT.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The board&apos;s evolving perceptions of cyber risk</strong></p><p class="fancy-box__body-text"><em>78 global CISOs share their advice on how to communicate cyber risk as business risk to C-suite peers and their board.</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/the-boards-evolving-perceptions-of-cyber-risk">DOWNLOAD FOR FREE</a></p></div></div><p>Internet-accessible MSSQL servers can be accessed via port 1433, which leaves the door open for ‘brute force’ password-guessing attempts by threat actors.</p><p>ESET noted that firms with weak passwords or improperly-managed servers are at particular risk, and cited an AhnLab <a href="https://asec.ahnlab.com/en/51343/"><u>report</u></a> from April which examined a case of <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware"><u>ransomware</u></a> installed on MSSQL servers as a result of easily-guessed credentials.</p><p>In all, telemetry data showed 1.7 billion failed password-guessing attempts against MSSQL between December 2022 and May 2023.</p><p>Even as threat actors have increased attacks against MSSQL, researchers noted reduced brute-force attempts on other commonly-used attack vectors. </p><p>Attacks on <a href="https://www.itpro.com/mobile/remote-access/368105/what-is-rdp"><u>Remote Desktop Protocol (RDP)</u></a>, which allows users to view and control desktops remotely and has been <a href="https://www.itpro.com/security/malware/researchers-uncover-novel-rdstealer-malware-targeting-remote-desktop-protocol"><u>exploited for malware such as RDStealer</u></a>, fell 22% from 17.9 billion to 15.8 billion across the period.</p><p>Brute-force attacks are among the <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers"><u>top password-cracking techniques hackers use</u></a>, and rely on businesses to employ poor strategies around their credentials such as allowing employees to re-use passwords or not enforcing complexity controls.</p><p>“With the rise of brute-force attacks against MSSQL, database admins should be reminded of the security benefits of Windows Authentication mode over mixed mode when setting up the database engine,” said Ladislav Janko, senior detection engineer at ESET.</p><p>“In Windows Authentication mode, SQL Server Authentication is disabled, compelling database users to connect through their Windows user account, which can be protected with an account lockout policy that effectively stops brute force attacks from progressing.</p><p>“If you can’t avoid using mixed mode, make sure passwords are strong and put the database behind a firewall or VPN, if possible.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>