{"id":16926,"date":"2020-05-29T11:25:00","date_gmt":"2020-05-29T11:25:00","guid":{"rendered":"https:\/\/icrowdnewswire.com\/?p=2574036"},"modified":"2020-05-29T11:25:00","modified_gmt":"2020-05-29T11:25:00","slug":"nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019","status":"publish","type":"post","link":"https:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/","title":{"rendered":"NSA: Russian govt hackers exploiting critical Exim flaw since 2019"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/content\/posts\/2020\/05\/28\/Sandworm.jpg\" alt=\"NSA: Russian govt hackers exploiting critical Exim flaw since 2019\" width=\"658\" height=\"242\" \/><\/p>\n<p>The U.S. National Security Agency (NSA) says that&nbsp;Russian military threat actors known as&nbsp;Sandworm Team have been exploiting a critical flaw in the Exim mail transfer agent (MTA) software since at least August 2019.<\/p>\n<p>The vulnerability tracked as CVE-2019-10149 and named &#8220;The Return of the WIZard&#8221; makes it possible for unauthenticated remote attackers to execute arbitrary commands&nbsp;as root on vulnerable mail servers &mdash; for some non-default server configurations &mdash; after sending a specially crafted email.<\/p>\n<p>&#8220;When the patch was released last year, Exim urged its users to update to the latest version,&#8221; the agency&nbsp;<a href=\"https:\/\/www.nsa.gov\/News-Features\/News-Stories\/Article-View\/Article\/2196511\/exim-mail-transfer-agent-actively-exploited-by-russian-gru-cyber-actors\/\" target=\"_blank\" rel=\"noopener noreferrer\">says<\/a>. &#8220;NSA adds its encouragement to immediately patch to mitigate against this still current threat.&#8221;<\/p>\n<h2>Attacks started after the Exim flaw got patched<\/h2>\n<p>GRU Main Center for Special Technologies (GTsST) hackers of&nbsp;Unit 74455&nbsp;have started exploiting victims&#8217; unpatched&nbsp;Exim serves&nbsp;after&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/millions-of-exim-mail-servers-exposed-to-local-remote-attacks\/\" target=\"_blank\" rel=\"noopener noreferrer\">an update was issued on June 5, 2019<\/a>, for users to patch their vulnerable servers.<\/p>\n<p>&#8220;The actors exploited victims using Exim software on their public-facing MTAs by sending a command in the &#8216;MAIL FROM&#8217; field of an SMTP (Simple Mail Transfer Protocol) message,&#8221; the NSA explains.<\/p>\n<p>The Exim vulnerability is used by the Russian&nbsp;<a href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/actor\/sandworm\" target=\"_blank\" rel=\"noopener noreferrer\">Sandworm<\/a>&nbsp;hackers to download a shell script&nbsp;from an attacker-controlled domain to &#8220;add privileged users, disable network security settings, update SSH configurations to enable additional remote access, execute an additional script to enable follow-on exploitation.&#8221;<\/p>\n<div>\n<figure class=\"image\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1109292\/2020\/Exploitation%20command.jpg\" alt=\"Sample exploitation command\" width=\"883\" height=\"134\" \/><figcaption><strong>Sample exploitation command<\/strong>&nbsp;(<em>NSA<\/em>)<\/figcaption><\/figure>\n<\/div>\n<p>BleepingComputer has been able to obtain the&nbsp;<em>script1.sh<\/em>&nbsp;script referenced in the exploit above, which allows us to see how the attack is conducted.<\/p>\n<div>\n<figure class=\"image\"><img loading=\"lazy\" decoding=\"async\" style=\"width: 569px; height: 395px;\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1109292\/2020\/image(2).png\" alt=\"Sandworm shell script1.sh script\" width=\"688\" height=\"478\" \/><figcaption><strong>Sandworm shell script1.sh script<\/strong><\/figcaption><\/figure>\n<\/div>\n<p>Upon execution, the script will execute a variety of commands that give them full access to the compromised server and any MySQL databases running on it.<\/p>\n<ul>\n<li>Adds a new &#8216;mysql_db&#8217; user with root privileges on the hacked server.<\/li>\n<li>Imports an&nbsp;SSH key the attackers can later use to gain access to the compromised server via SSH.<\/li>\n<li>Executes&nbsp;base64 encoded commands that will connect to a remote site and download commands\/executables to launch&nbsp;on the hacked machines.<\/li>\n<li>Adds&nbsp;a MySQL user named &#8216;mysqldb&#8217; running MySQL instances and gives it full access to all the databases on the server.<\/li>\n<li>Restarts sshd and MySQL daemons<\/li>\n<\/ul>\n<p>For two of the Base64 encoded commands, Sandworm&#8217;s script will check the running processes for &#8216;Little Snitch&#8217;, a popular third-party macOS firewall.<\/p>\n<p>If the process is present, the script will not continue executing the command, as seen in the code snippet below.<\/p>\n<div>\n<figure class=\"image\"><img loading=\"lazy\" decoding=\"async\" class=\"b-lazy b-loaded\" style=\"width: 587px; height: 309px;\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1109292\/2020\/image%20(1).png\" alt=\"LittleSnitch checks\" width=\"634\" height=\"334\" \/><figcaption><strong>LittleSnitch checks<\/strong><\/figcaption><\/figure>\n<\/div>\n<h2>Mitigation, detection, and defense&nbsp;measures<\/h2>\n<p>As mitigation measures, the NSA recommends patching their Exim&nbsp;servers immediately by installing version 4.93 or newer.<\/p>\n<p data-inc=\"1\">&#8220;Administrators can update Exim Mail Transfer Agent software through their Linux distribution&rsquo;s package manager or by downloading the latest version from https:\/\/exim.org\/mirrors.html,&#8221;&nbsp;the agency says.<\/p>\n<p>&#8220;Using a previous version of Exim&nbsp;leaves a system vulnerable to exploitation. System administrators should continually check software versions and update as new versions become available.&#8221;<\/p>\n<p>The NSA also provides Indicators of Compromise and instructions on how to detect exploit attempts and unauthorized changes within this&nbsp;<a href=\"https:\/\/media.defense.gov\/2020\/May\/28\/2002306626\/-1\/-1\/0\/CSA%20Sandworm%20Actors%20Exploiting%20Vulnerability%20in%20Exim%20Transfer%20Agent%2020200528.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">security advisory<\/a>.<\/p>\n<h2>Warnings of attacks exploiting&nbsp;CVE-2019-10149<\/h2>\n<p>Even though&nbsp;the Exim&nbsp;flaw is known to have been exploited in the wild since at least June 9, 2019 (<a href=\"https:\/\/twitter.com\/freddieleeman\/status\/1137729455181500421\" target=\"_blank\" rel=\"noopener noreferrer\">1<\/a>,&nbsp;<a href=\"https:\/\/twitter.com\/0xAmit\/status\/1139165487093420035\" target=\"_blank\" rel=\"noopener noreferrer\">2<\/a>), there still are millions of unpatched servers vulnerable to attacks.<\/p>\n<p>According to a quick Shodan search, vulnerable versions of Exim are currently running on about Internet-exposed&nbsp;<a href=\"https:\/\/www.shodan.io\/search?query=product%3Aexim+-4.92\" target=\"_blank\" rel=\"noopener noreferrer\">2,481,000 servers<\/a>, with more than&nbsp;<a href=\"https:\/\/www.shodan.io\/search?query=product%3Aexim+and+%224.92%22\" target=\"_blank\" rel=\"noopener noreferrer\">2,467,000 servers<\/a>&nbsp;running the patched Exim&nbsp;4.93 release.&nbsp;<\/p>\n<p>Microsoft issued a warning in June 2019&nbsp;about an active Linux worm targeting the&nbsp;Remote Code Execution (RCE)&nbsp;CVE-2019-10149&nbsp;Exim&nbsp;mail server vulnerability, saying that&nbsp;Azure servers can still be infected or hacked by abusing the flaw even though&nbsp;existing mitigations could&nbsp;block the malware&#8217;s worm functionality.<\/p>\n<p>One month later, attackers also&nbsp;<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-exploit-jira-exim-linux-servers-to-keep-the-internet-safe\/\" target=\"_blank\" rel=\"noopener noreferrer\">started exploiting vulnerable Exim servers<\/a>&nbsp;trying to install the&nbsp;Watchbog Linux trojan with the end goal of adding the infected boxes to a Monero cryptomining botnet.<\/p>\n<p class=\"tags\">\n<div><strong>See Campaign: <\/strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/millions-of-exim-mail-servers-exposed-to-local-remote-attacks\/\" target=\"_blank\">https:\/\/www.bleepingcomputer.com\/news\/security\/millions-of-exim-mail-servers-exposed-to-local-remote-attacks\/<\/a><br \/><b>Contact Information:<\/b><br \/>Sergiu Gatlan<\/p>\n<p><b>Tags:<\/b><br \/><a href=\"\"><\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/news-category\/wire\/\" rel=\"category tag\">Wire<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/global-regions\/united-states\/\" rel=\"category tag\">United States<\/a>, <a href=\"https:\/\/icrowdnewswire.com\/category\/language\/english\/\" rel=\"category tag\">English<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"\" alt=\"image\" width=\"400\" height=\"300\" class=\"cwdfimg\" \/><\/div>\n<div>\n<h3>Contact Information:<\/h3>\n<p>Sergiu Gatlan<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The U.S. National Security Agency (NSA) says that&nbsp;Russian military threat actors known as&nbsp;Sandworm Team have been exploiting a critical flaw in the Exim mail transfer agent (MTA) software since at least August 2019. The vulnerability tracked as CVE-2019-10149 and named &ldquo;The Return of the WIZard&rdquo; makes it possible for unauthenticated remote attackers to execute arbitrary &hellip; <a href=\"https:\/\/icrowdnewswire.com\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/\">Continue reading <span>NSA: Russian govt hackers exploiting critical Exim flaw since 2019<\/span><\/a> <a href=\"https:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/\" class=\"more-link\">Continue Reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":107,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,22,54],"tags":[],"class_list":["post-16926","post","type-post","status-publish","format-standard","hentry","category-english","category-united-states","category-wire"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>NSA: Russian govt hackers exploiting critical Exim flaw since 2019 - Business<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NSA: Russian govt hackers exploiting critical Exim flaw since 2019 - Business\" \/>\n<meta property=\"og:description\" content=\"The U.S. National Security Agency (NSA) says that&nbsp;Russian military threat actors known as&nbsp;Sandworm Team have been exploiting a critical flaw in the Exim mail transfer agent (MTA) software since at least August 2019. The vulnerability tracked as CVE-2019-10149 and named &ldquo;The Return of the WIZard&rdquo; makes it possible for unauthenticated remote attackers to execute arbitrary &hellip; Continue reading NSA: Russian govt hackers exploiting critical Exim flaw since 2019 Continue Reading &rarr;\" \/>\n<meta property=\"og:url\" content=\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/\" \/>\n<meta property=\"og:site_name\" content=\"Business\" \/>\n<meta property=\"article:published_time\" content=\"2020-05-29T11:25:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.bleepstatic.com\/content\/posts\/2020\/05\/28\/Sandworm.jpg\" \/>\n<meta name=\"author\" content=\"Sarim Pixako\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sarim Pixako\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/\",\"url\":\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/\",\"name\":\"NSA: Russian govt hackers exploiting critical Exim flaw since 2019 - Business\",\"isPartOf\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#primaryimage\"},\"image\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.bleepstatic.com\/content\/posts\/2020\/05\/28\/Sandworm.jpg\",\"datePublished\":\"2020-05-29T11:25:00+00:00\",\"author\":{\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/c2a30f1f67fb81890ad62e1daf092377\"},\"breadcrumb\":{\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#primaryimage\",\"url\":\"https:\/\/www.bleepstatic.com\/content\/posts\/2020\/05\/28\/Sandworm.jpg\",\"contentUrl\":\"https:\/\/www.bleepstatic.com\/content\/posts\/2020\/05\/28\/Sandworm.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/ipsnews.net\/business\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NSA: Russian govt hackers exploiting critical Exim flaw since 2019\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/ipsnews.net\/business\/#website\",\"url\":\"https:\/\/ipsnews.net\/business\/\",\"name\":\"Business\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/ipsnews.net\/business\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/c2a30f1f67fb81890ad62e1daf092377\",\"name\":\"Sarim Pixako\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7f9acce50c9b44bcec82e92168491959d754000e22e22a437856e37c38599249?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7f9acce50c9b44bcec82e92168491959d754000e22e22a437856e37c38599249?s=96&d=mm&r=g\",\"caption\":\"Sarim Pixako\"},\"sameAs\":[\"https:\/\/icrowdnewswire.com\/fc\"],\"url\":\"https:\/\/ipsnews.net\/business\/author\/sarim-pixako\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NSA: Russian govt hackers exploiting critical Exim flaw since 2019 - Business","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/","og_locale":"en_US","og_type":"article","og_title":"NSA: Russian govt hackers exploiting critical Exim flaw since 2019 - Business","og_description":"The U.S. National Security Agency (NSA) says that&nbsp;Russian military threat actors known as&nbsp;Sandworm Team have been exploiting a critical flaw in the Exim mail transfer agent (MTA) software since at least August 2019. The vulnerability tracked as CVE-2019-10149 and named &ldquo;The Return of the WIZard&rdquo; makes it possible for unauthenticated remote attackers to execute arbitrary &hellip; Continue reading NSA: Russian govt hackers exploiting critical Exim flaw since 2019 Continue Reading &rarr;","og_url":"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/","og_site_name":"Business","article_published_time":"2020-05-29T11:25:00+00:00","og_image":[{"url":"https:\/\/www.bleepstatic.com\/content\/posts\/2020\/05\/28\/Sandworm.jpg","type":"","width":"","height":""}],"author":"Sarim Pixako","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sarim Pixako","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/","url":"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/","name":"NSA: Russian govt hackers exploiting critical Exim flaw since 2019 - Business","isPartOf":{"@id":"https:\/\/ipsnews.net\/business\/#website"},"primaryImageOfPage":{"@id":"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#primaryimage"},"image":{"@id":"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#primaryimage"},"thumbnailUrl":"https:\/\/www.bleepstatic.com\/content\/posts\/2020\/05\/28\/Sandworm.jpg","datePublished":"2020-05-29T11:25:00+00:00","author":{"@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/c2a30f1f67fb81890ad62e1daf092377"},"breadcrumb":{"@id":"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#primaryimage","url":"https:\/\/www.bleepstatic.com\/content\/posts\/2020\/05\/28\/Sandworm.jpg","contentUrl":"https:\/\/www.bleepstatic.com\/content\/posts\/2020\/05\/28\/Sandworm.jpg"},{"@type":"BreadcrumbList","@id":"http:\/\/ipsnews.net\/business\/2020\/05\/29\/nsa-russian-govt-hackers-exploiting-critical-exim-flaw-since-2019\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/ipsnews.net\/business\/"},{"@type":"ListItem","position":2,"name":"NSA: Russian govt hackers exploiting critical Exim flaw since 2019"}]},{"@type":"WebSite","@id":"https:\/\/ipsnews.net\/business\/#website","url":"https:\/\/ipsnews.net\/business\/","name":"Business","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/ipsnews.net\/business\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/c2a30f1f67fb81890ad62e1daf092377","name":"Sarim Pixako","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/ipsnews.net\/business\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7f9acce50c9b44bcec82e92168491959d754000e22e22a437856e37c38599249?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7f9acce50c9b44bcec82e92168491959d754000e22e22a437856e37c38599249?s=96&d=mm&r=g","caption":"Sarim Pixako"},"sameAs":["https:\/\/icrowdnewswire.com\/fc"],"url":"https:\/\/ipsnews.net\/business\/author\/sarim-pixako\/"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/16926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/users\/107"}],"replies":[{"embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/comments?post=16926"}],"version-history":[{"count":1,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/16926\/revisions"}],"predecessor-version":[{"id":16927,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/posts\/16926\/revisions\/16927"}],"wp:attachment":[{"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/media?parent=16926"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/categories?post=16926"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ipsnews.net\/business\/wp-json\/wp\/v2\/tags?post=16926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}