logo

Contractor Software Targeted via Microsoft SQL Server Loophole

ID: e8556469-96c2-51cf-be41-6ae4946a3f93

STIX ID: report--e8556469-96c2-51cf-be41-6ae4946a3f93

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-09-18

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Researchers observed active intrusions targeting Foundation accounting software used by contractors, where exposed MSSQL access (TCP 4243) and default or brute-forced 'sa' credentials allow attackers to gain database-level and shell access; attacks are automated and widespread across construction sub-industries, prompting recommendations to rotate credentials and remove public Internet exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.