Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

171–180 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#171

Microsoft filed this late today with the SEC[1] just before they stopped accepting new filings for the day under their new Cybersecurity Incident disclosure rule[2]. FWIW, two other publicly traded companies disclosed[3] their breaches since the rule went into affect last month. [1] https://www.sec.gov/Archives/edgar/data/789019/0001193125240... [2] https://www.sec.gov/news/press-release/2023-139 [3] https://last10k.…

Actually there has been more, e.g. LoanDepot, Inc [1], and then various amended 8-Ks. I’ve been hacking on a side project to parse the 8-K data which is all over the place, including some companies still reporting under old “items” like 8.01 vs the new 1.05 material cybersecurity incident item.

If folks are interested in this space, I just got the mailing list [2] running last night and you can see a list of all the current incidents on my Incident Tracker [3].

I have many more data points I plan on tracking as well as adding 10-K GRC items to the list (potentially helpful for CISOs, other risk managers and investors to eval a companies risk management maturity).

Welcome any feedback!

[1] https://www.board-cybersecurity.com/incidents/tracker/202401...

[2] https://www.board-cybersecurity.com/alerts/

[3] https://www.board-cybersecurity.com/incidents/tracker/

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#172
post #134

Why do they say "nation state actor", isn't "state actor" the correct term? I thought Russia, like the UK and many other states, is a multinational state, including numerous languages and cultures.

Maybe to make it clear to American readers it's not Iova?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#173
post #168

Earlier quoted context omitted.

That may be how Microsoft would like to portray it but I disagree. A production system is a system that is operated to serve its actual purpose rather than being used as a development or testing environment. From the point of view of in-house IT, the company's email server is a production system. It is what they produce for their in-house customers.

Test environments serve the production purpose of testing software.

That's pure sophistry.

A system used by the cybersecurity team for its day to day work was breached by attackers constantly trying to break into customer systems.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#174
post #98

>Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium How do they identify those groups?

Easily, they have "vam pizda" and "blyat" sprayed around in their malicious scripts.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#175
post #70
post #49

I wonder which mail client the execs were using. If Outlook, their messages would be already harvested by 700+ companies[0] and another leak wouldn't be an issue. [0] https://news.ycombinator.com/item?id=38441710 [0] https://news.ycombinator.com/item?id=38953618

Ever since Delve was introduced, Microsoft Outlook has felt weird to me

I’m not familiar with Delve. Care to elaborate?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#176

Earlier quoted context omitted.

In the context of an outage at a service provider this slightly sloppy language is sufficient to convey all relevant meaning. In the current context, this language is part of a pattern to carefully choose words in such a way as to downplay what has happened. As I said, the work of the CEO, the cybersecurity team and the legal team is part of the overall production process at a software company.

Okay, but then why also not consider chairs breaking in the office to mean part of the production is down? Or a coffee machine?

If my coffee machine suddenly stopped working it would definitely have a detrimental effect on production. I can guarantee you that :)

But in general I would say routine janitorial maintenance issues don't have quite the same potential to affect production as Russian criminals reading the email of Microsoft's cybersecurity team.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#177
post #114
post #108

Earlier quoted context omitted.

Yes, and I think most people would consider it a vulnerability if an authentication system doesn't rate-limit or otherwise slow/stop "password spray" attacks.

You can rate limit individual users but password spray attacks use a large number of accounts to remain undetected in a authentication system used by an even more users.

{rolls eyes}

This is precisely the kind of 1990's level basic heuristic that this company cites as part of their Sentinel security system.

Trying to excuse a breach by 'the attacker tried a few passwords against lots of different accounts' is not compelling.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#178

Earlier quoted context omitted.

> Why do they say "nation state actor" A Nation-State is the idea of a homogenous nation governed by its own sovereign state—where each state contains one nation.

And that definition doesn't describe the Russian Federation. There are many nations within Russia, ones you may have heard of are Bashkortostan (in the news this month due to protests) and Chechnya (civil wars in the 1990s). It is not a homogeneous federation. https://en.wikipedia.org/wiki/Republics_of_Russia

Indeed, the term doesn't describe any of the 3 countries it's most often applied to (the other being China and the USA).

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#179
post #102

Earlier quoted context omitted.

But how do they know that it's sponsored by Russia? They saw the paychecks?

They’ve been around for a while and identified by several governments. “NOBELIUM is an advanced persistent threat group also known as APT29, which is publicly attributed to the Russian government and specifically to the Foreign Intelligence Service of the Russian Federation (SVR)” https://blogs.blackberry.com/en/2023/03/nobelium-targets-eu-...

It still doesn't answer how they know that: 1) they were hacked by that exact group 2) that group is sponsored by the Russian government.

The only evidence I've seen before in cases like this one was that they found that the hacks happened during Russia's working hours (i.e. Moscow timezone), and that they found some word in Cyrillic in some of the shell scripts. Which is honestly not hard to pull off if you want to hide your true identity. Not saying Russia is not interested in those hacks, but a lot of far-reaching conclusions are often quickly made based on such weak assumptions.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#180

Earlier quoted context omitted.

They are just making it up. Security people seems to be of the militaristic type ofent, so I guess they add a slive of war mongering to it to to play ball. Iran, North Korea and what not. Very convenient since it is not falsifiable in practice.

They are certainly identifiable from their work. State hackers are professionals and they work like other professionals do; they work 9-5 in their local time zone and they have modular implants with code reuse. Amateurs aren't like this.

That's basically the only argument I've heard so far - if a hacking activity happens between 06:00 UTC and 14:00 UTC then it must be the Russians, otherwise it's someone else. Doesn't sound like a very strong argument?

"Modular implants with code reuse" - sounds like exploit kits you can buy on hacking forums.

Post reply on HN