Contractor Software Targeted via Microsoft SQL Server Loophole
ID: e8556469-96c2-51cf-be41-6ae4946a3f93
STIX ID: report--e8556469-96c2-51cf-be41-6ae4946a3f93
Feed Name: Dark Reading
Threat Score
Researchers observed active intrusions targeting Foundation accounting software used by contractors, where exposed MSSQL access (TCP 4243) and default or brute-forced 'sa' credentials allow attackers to gain database-level and shell access; attacks are automated and widespread across construction sub-industries, prompting recommendations to rotate credentials and remove public Internet exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
