Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

101–110 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#101
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

Not to downplay the severity but honestly, every breach I read about seems “serious” but very rarely does anything of consequence happen with these events.

Azure was owned pretty hard a while back, very little was ever heard of it again.

Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#102
post #44

Earlier quoted context omitted.

> It’s ok to call them countries, hackers, and intrusions. It's not if you want to do business in that country. Or if you annoy allies of that country (accusing certain countries might get senators breathing down your neck!). You are accusing a government of committing a crime, or at least a wildly unethical behavior. Those are huge charges. To your point, I wish they could be more direct, but... > Microsoft got hack…

It is government sponsored. It says in the article. >Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium.

But how do they know that it's sponsored by Russia? They saw the paychecks?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#103
post #90
post #54

Earlier quoted context omitted.

I'm guessing they don't know what a password spray is?

What is it? Just spam a form with passwords?

Well, your "legacy non production test tenant" can be opened by just guessing passwords, and it allows access to "very much in use production non-test" tenants, then you could say MS has a vulnerability. It may not be a buffer overflow, but it is a vulnerability nonetheless.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#104
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

I like this bit

  ... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents. 
Yeah, at least they make a very small percentage of all Microsoft employees I guess

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#105
post #65

>Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts I have so many questions from this sentence alone. What did they password spray? Microsoft's internal identity provider? Was the non-prod system inte…

[dead]

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#108
post #103
post #90

Earlier quoted context omitted.

What is it? Just spam a form with passwords?

Well, your "legacy non production test tenant" can be opened by just guessing passwords, and it allows access to "very much in use production non-test" tenants, then you could say MS has a vulnerability. It may not be a buffer overflow, but it is a vulnerability nonetheless.

Yes, and I think most people would consider it a vulnerability if an authentication system doesn't rate-limit or otherwise slow/stop "password spray" attacks.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#109

Interesting that they seem to suggest that applying security is now more important than avoiding service disruptions. This may be the hopeful dawn of a new era.

Well well well.. how the turn tables.

It's karma after years of my windows machine forcing a restart for a security update while I'm working on something in the middle of the day..

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#110
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

Not to downplay the severity but honestly, every breach I read about seems “serious” but very rarely does anything of consequence happen with these events. Azure was owned pretty hard a while back, very little was ever heard of it again. Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?

How do you know if nothing happens? It isn't like the people siphoning, selling, or purchasing this data are broadcasting their wins on news aggregators.
Post reply on HN