Construction firms breached in brute force attacks on accounting software
ID: bc1a15a0-cfb7-501c-a3bb-6dc4e4df9d24
STIX ID: report--bc1a15a0-cfb7-501c-a3bb-6dc4e4df9d24
Feed Name: Bleeping Computer
Threat Score
Huntress observed aggressive brute-force attacks targeting on-premise Foundation accounting MSSQL servers (often exposed on TCP 4243) that use default/weak admin credentials ('sa' and 'dba'); attackers are enabling xp_cmdshell to execute OS commands and have achieved successful breaches across plumbing, HVAC, concrete and other construction firms. Recommendation: rotate credentials, remove or restrict public MSSQL access, and harden affected servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
