Interesting that they seem to suggest that applying security is now more important than avoiding service disruptions. This may be the hopeful dawn of a new era.
Microsoft actions following attack by nation state actor Midnight Blizzard
111–120 of 204 posts
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#112"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.
I like this bit ... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents. Yeah, at least they make a very small percentage of all Microsoft employees I guess
"To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems."
So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#113> access a very small percentage of Microsoft corporate email accounts Ok, so far so good. > including members of our senior leadership team Ahhh, so maybe the attackers were after the senior leadership team and therefore stopped at the "very small percentage".
Seems weird to word it as “a very small percentage” instead of “a very small number” unless the number was a little bigger than they want to admit.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#114Earlier quoted context omitted.
Well, your "legacy non production test tenant" can be opened by just guessing passwords, and it allows access to "very much in use production non-test" tenants, then you could say MS has a vulnerability. It may not be a buffer overflow, but it is a vulnerability nonetheless.
Yes, and I think most people would consider it a vulnerability if an authentication system doesn't rate-limit or otherwise slow/stop "password spray" attacks.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#115Oh god they're russian. That means they're evil !
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#116Earlier quoted context omitted.
Crowdstrike. FireEye.
Definitely agree that Crowdstrikes naming veers past what is necessary. They even draw up supervillain graphics for them. https://www.crowdstrike.com/adversaries/arcane-kitten/
Why are we modelling threat actors/"adversaries" as a video game bestiary? Or meteorological phenomena in the case of MS?
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#117They should look at upgrading their Entra ID plan to P2 in order to protect against these attacks.
And all things considered, an AI security assistant like Copilot might be a good investment too, if they lack highly skilled front line security staff. Not to mention, AI generated automated playbooks in Sentinel to automatically apply Zero Trust principles! I also wonder if they had upgraded all of their Subscriptions to Defender for Cloud CSPM Tier 2 in order to use the premium Cloud Security Attack Graph explorer,…
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#118"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.
Not to downplay the severity but honestly, every breach I read about seems “serious” but very rarely does anything of consequence happen with these events. Azure was owned pretty hard a while back, very little was ever heard of it again. Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#119Fine, I bet the password was Password123!, but then "they used account's permissions" to access various corporate emails. How is that even possible? What does it mean "they used the account's permissions"? Are you telling me there was no privilege separation between a tenant test environment and the internal domain? That the tenant system was not in its own isolated network? This is absolutely insane. Whenever I read stuff like that I wonder if some junior IT employee didn't just buy a new home for cash few months ago. I'm all for "don't look for malice where incompetence is a sufficient explanation", but that's just a little too much incompetence to be believable.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#120Earlier quoted context omitted.
Yes, and I think most people would consider it a vulnerability if an authentication system doesn't rate-limit or otherwise slow/stop "password spray" attacks.
You can rate limit individual users but password spray attacks use a large number of accounts to remain undetected in a authentication system used by an even more users.