SME Times is powered by   
Search News
Just in:   • WEF 2026: Accessibility, affordability, and personalisation key to boost women’s health, say experts  • Assam - the only state in the country to directly engage in oil production, claims CM Sarma  • Avenues for investments in Assam opened up, says CM Himanta Biswa Sarma  • FDI flows to India surged by 73 pc in 2025: UNCTAD  • S. Korean economy grows 1 pc in 2025; Q4 GDP contracts 0.3 pc 
Last updated: 24 Nov, 2022  

Microsoft.9.Thmb.jpg Hackers exploited discontinued web server at Tata Power: Microsoft

Microsoft.9.jpg
   Top Stories
» Gold, silver prices ease after Trump backs off from tariff threats on Europe
» WEF 2026: Experts See AI as a Tool to Augment, Not Replace
» Gold prices jump over 4 pc to hit record high
» India’s textile sector is a powerful job-creating engine of growth: PM Modi
» India, EU likely to clinch FTA deal by Jan 27
IANS | 24 Nov, 2022
Microsoft has warned that state-sponsored hackers are attacking critical energy infrastructure in India via exploiting a discontinued web server, with the most recent attack it observed was on Tata Power in October.

Microsoft security researchers discovered a vulnerable open-source component in the "Boa web server" still being used in routers, security cameras and popular software development kits (SDKs), despite its retirement in 2005.

Tata Power last month admitted it was hit by a cyber attack on its IT infrastructure. The power company, however, said that all its critical operational systems were functioning normally.

The cyber attack on Tata Power was the handiwork of Hive ransomware group thatAhas victimised over 1,300 companies worldwide, receiving approximately $100 million in ransom payments, according to a joint advisory by the FBI, the US Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services last week.

Microsoft said it continues to see attackers attempting to exploit Boa vulnerabilities, indicating that it is still targeted as an attack vector.

A report published by cybersecurity company Recorded Future in April this year first detailed suspected electrical grid intrusion activity and implicated common IoT devices.

While investigating the attack activity, Microsoft researchers assessed the vulnerable component to be the now-retired Boa web server, which is often used to access settings and management consoles and sign-in screens in devices.

"Without developers managing the Boa web server, its known vulnerabilities could allow attackers to silently gain access to networks by collecting information from files," said the tech giant.

Moreover, those affected may be unaware that their devices run services using the discontinued Boa web server, and that firmware updates and downstream patches do not address its known vulnerabilities.

"Microsoft assesses that Boa servers were running on the IP addresses on the list of IOCs published by Recorded Future at the time of the report's release and that the electrical grid attack targeted exposed IoT devices running Boa," said the security researchers.

Tata Power Company had said that some of its IT systems were impacted by the cyber attack.

According to Microsoft, the popularity of the Boa web server displays the potential exposure risk of an insecure supply chain, even when security best practices are applied to devices in the network.

"In critical infrastructure networks, being able to collect information undetected prior to the attack allows the attackers to have much greater impact once the attack is initiated, potentially disrupting operations that can cost millions of dollars and affect millions of people," it added.

 
Print the Page
Add to Favorite
 
Share this on :
 

Please comment on this story:
 
Subject :
Message:
(Maximum 1500 characters)  Characters left 1500
Your name:
 

 
  Customs Exchange Rates
Currency Import Export
US Dollar
₹91.2
₹89.5
UK Pound
₹123.35
₹119.35
Euro
₹107
₹103.35
Japanese Yen ₹57.9 ₹56.1
As on 22 Jan, 2026
  Daily Poll
Will the India-EU "Mother of All Deals" help your MSME?
 Yes - Alternative To US
 No - EU Compliance is hard
 Maybe - if the fine print is small biz ready
 Not Sure - Need to See Final Text
  Commented Stories
 
 
About Us  |   Advertise with Us  
  Useful Links  |   Terms and Conditions  |   Disclaimer  |   Contact Us  
Follow Us : Facebook Twitter