Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

11–20 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#13
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

At least for the "Midnight Blizzard" part of the title, it's the result of a naming framework [0] for threat actors that Microsoft has been using since April 2023. I agree it sounds weird.

[0] https://learn.microsoft.com/en-us/microsoft-365/security/int...

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#14
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

Russia hacks, but so do China, North Korea, Iran and Ukraine. They all have bagged large targets. It could be any of them but could be someone else as well.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#15
post #8

> access a very small percentage of Microsoft corporate email accounts Ok, so far so good. > including members of our senior leadership team Ahhh, so maybe the attackers were after the senior leadership team and therefore stopped at the "very small percentage".

Seems weird to word it as “a very small percentage” instead of “a very small number” unless the number was a little bigger than they want to admit.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#16
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

At least for the "Midnight Blizzard" part of the title, it's the result of a naming framework [0] for threat actors that Microsoft has been using since April 2023. I agree it sounds weird. [0] https://learn.microsoft.com/en-us/microsoft-365/security/int...

The naming framework for these groups isn't even consistent, with every vendor having their own scheme. Midnight Animal to one vendor is Dancing Bear to another and known by Wet Cat to yet another.

They all sound like bad translations to bargain-bin porno movies.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#17
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

> It’s ok to call them countries, hackers, and intrusions. It's not if you want to do business in that country. Or if you annoy allies of that country (accusing certain countries might get senators breathing down your neck!). You are accusing a government of committing a crime, or at least a wildly unethical behavior. Those are huge charges. To your point, I wish they could be more direct, but... > Microsoft got hack…

>> It is not known whether this hacking group is private, government sponsored, or government run.

Coming from Russia, that's a distinction without a difference.

Sure, private groups can 'freelance', but not without at least tacit permission from the FSB, GRU, and/or SVR (more accurately, cant freelance for long). Especially so for sch a high visibility target such as Microsoft.

And when the RU govt isdues a denial, it's confirmed.

But still no reason for MS to escalate the wording. They put enough in there that anyone with a clue knows it's serious.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#20
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

It largely boils down to the same reason scientists classify animals into taxonomies. It helps to have a framework for classifying the groups so you can refer back to them in the future.

Going back to my example with taxonomies: Yeah, you got bit by a spider, but exactly which kind of spider bit you? What do we know about those kinds of spiders, e.g. are they known for being venomous or not, does their bite have a well-known reaction in humans, etc.

Post reply on HN