Sign up for our daily briefing

Make your busy days simpler with the Axios AM and PM newsletters. Catch up on what's new and why it matters in just 5 minutes.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on the day's biggest business stories

Subscribe to the Axios Closer newsletter for insights into the day’s business news and trends and why they matter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Sign up for Axios Pro Rata

Dive into the world of dealmakers across VC, PE and M&A with Axios Pro Rata. Delivered daily to your inbox by Dan Primack and Kia Kokalitcheva.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Sports news worthy of your time

Binge on the stats and stories that drive the sports world with the Axios Sports newsletter. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Tech news worthy of your time

Get our smart take on technology from the Valley and D.C. with Axios Login. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Get the inside stories

Get an insider's guide to the new White House with Axios Sneak Peek. Sign up for free.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Denver news?

Get a daily digest of the most important stories affecting your hometown with Axios Denver

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Des Moines news?

Get a daily digest of the most important stories affecting your hometown with the Axios Des Moines newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Twin Cities news?

Get a daily digest of the most important stories affecting your hometown with Axios Twin Cities

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Tampa Bay news?

Get a daily digest of the most important stories affecting your hometown with the Axios Tampa Bay newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Charlotte news?

Get a daily digest of the most important stories affecting your hometown with Axios Charlotte

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Nashville news?

Get a daily digest of the most important stories affecting your hometown with the Axios Nashville newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Columbus news?

Get a daily digest of the most important stories affecting your hometown with the Axios Columbus newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Dallas news?

Get a daily digest of the most important stories affecting your hometown with the Axios Dallas newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Austin news?

Get a daily digest of the most important stories affecting your hometown with the Axios Austin newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Atlanta news?

Get a daily digest of the most important stories affecting your hometown with the Axios Atlanta newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Philadelphia news?

Get a daily digest of the most important stories affecting your hometown with the Axios Philadelphia newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top Chicago news?

Get a daily digest of the most important stories affecting your hometown with the Axios Chicago newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Sign up for Axios NW Arkansas

Stay up-to-date on the most important and interesting stories affecting NW Arkansas, authored by local reporters

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Want a daily digest of the top DC news?

Get a daily digest of the most important stories affecting your hometown with the Axios DC newsletter.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

A member of the Red Hacker Alliance group in Dongguan in China's southern Guangdong province. Photo: Nicolas Asfouri/AFP via Getty Images

Foreign hackers are suspected of compromising organizations in the technology, defense, healthcare, energy and education industries in the U.S. and other countries, cybersecurity firm Palo Alto Networks said late Sunday.

Why it matters: The National Security Agency contributed to Palo Alto Networks' report amid ongoing efforts to crack down on hackers who've been trying to steal critical data from targets including U.S. defense contractors, notes CNN, which first reported the breach.

What they found: "Through global telemetry, we believe that the actor targeted at least 370 Zoho [software] ... in the United States alone," Palo Alto Networks said in a blog post late Sunday of the attack that it said began Sept. 17 and continued through early October.

  • "Given the scale, we assess that these scans were largely indiscriminate in nature as targets ranged from education to Department of Defense entities," the post added.
  • Hackers gained access via a vulnerability in software used to manage network passwords.
"Ultimately, the actor was interested in stealing credentials, maintaining access and gathering sensitive files from victim networks for exfiltration."
— Excerpt from Palo Alto Network's report

Of note: Cybersecurity company Mandiant found evidence linking the ruling Chinese Communist Party to hack attacks on the U.S. government, businesses and American infrastructure earlier this year.

  • The NSA and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) are working to combat such threats, CNN notes.

What they're saying: Eric Goldstein, executive assistant director for cybersecurity at CISA, said in an emailed statement that CISA worked with Palo Alto Network via the Joint Cyber Defense Collaborative (JCDC) to "understand, amplify, and drive action in response to the activity identified in this report."

  • "This partnership reflects the value of the JCDC, in which government and the private sector work together to gain visibility and reduce risks that no organization can achieve alone," Goldstein added.
  • Morgan Adamski, director of the NSA's Cybersecurity Collaboration Center, said in an emailed statement that the agency is "delivering real-time impact to our partners and the defense of the nation."
  • Wendi Whitmore, senior vice president of Palo Alto Networks Unit 42, said in an emailed statement that the research "underscores the importance of rapid patch management, real time threat intelligence sharing, and the ability to rapidly detect new threat activity within environments."
  • Whitmore urged organizations that use Zoho software to immediately address any vulnerabilities before resetting passwords.

What to watch: The Biden administration announced last month plans to create a bureau of cyberspace and digital policy and a new envoy to oversee critical and emerging technology in response to the hack attacks, pending congressional approval.

Editor's note: This story has been updated with Eric Goldstein's and Morgan Adamski's statement.

Go deeper

Updated Jan 14, 2022 - World

U.S. confirms Russia arrested REvil ransomware hackers

Russian President Vladimir Putin speaking in Moscow in June 2021. Photo: Alexei Nikolsky/TASS via Getty Images

Russia's security agency said Friday it arrested members of the Russia-based cyber gang REvil that was responsible for multiple massive ransomware attacks against U.S. companies last year.

The latest: A senior administration official confirmed on Friday afternoon that Russia informed the U.S. that it arrested the alleged hackers, including an individual responsible for the cyberattack that crippled the Colonial Pipeline.

1 min ago - World

Scoop: Ukraine tells senators post-invasion sanctions are no help

Zelensky. Photo: Johanna Geron/POOL/AFP via Getty Images

Ukrainian President Volodymyr Zelensky told U.S. senators visiting Kyiv this week that waiting to impose sanctions on Russia until after an invasion is of no use to Ukraine, according to four sources familiar with the discussions.

Why it matters: The Senate is currently working on a major sanctions package to deter Russia from attacking Ukraine. Democrats and Republicans are united in their support for Ukraine, but divided over whether it would be more effective to sanction Russia now to signal resolve, or hold up the threat of future sanctions to demonstrate the high costs of an invasion.

Starbucks drops worker vaccine or test requirement after SCOTUS ruling

Photo: Jakub Porzycki/NurPhoto via Getty Images

Starbucks has dropped plans to require that U.S. workers get the COVID vaccine or submit to weekly testing, the company announced Tuesday in a memo to employees.

Why it matters: The company's decision comes in response to the Supreme Court's ruling last week to block the Biden administration's COVID-19 vaccine-or-test requirement for large employers.