Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

111–120 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#111

Interesting that they seem to suggest that applying security is now more important than avoiding service disruptions. This may be the hopeful dawn of a new era.

It won’t be. Everyone will forget about this in a week and it will be BAU. Like every other breach.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#112
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

I like this bit ... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents. Yeah, at least they make a very small percentage of all Microsoft employees I guess

Also this:

"To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems."

So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#113
post #8

> access a very small percentage of Microsoft corporate email accounts Ok, so far so good. > including members of our senior leadership team Ahhh, so maybe the attackers were after the senior leadership team and therefore stopped at the "very small percentage".

Seems weird to word it as “a very small percentage” instead of “a very small number” unless the number was a little bigger than they want to admit.

I’ve noticed in PR it’s very common (I’d say even standard practice) to use percentages to hide absolute numbers, and vice versa

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#114
post #108
post #103

Earlier quoted context omitted.

Well, your "legacy non production test tenant" can be opened by just guessing passwords, and it allows access to "very much in use production non-test" tenants, then you could say MS has a vulnerability. It may not be a buffer overflow, but it is a vulnerability nonetheless.

Yes, and I think most people would consider it a vulnerability if an authentication system doesn't rate-limit or otherwise slow/stop "password spray" attacks.

You can rate limit individual users but password spray attacks use a large number of accounts to remain undetected in a authentication system used by an even more users.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#116
post #57

Earlier quoted context omitted.

Crowdstrike. FireEye.

Definitely agree that Crowdstrikes naming veers past what is necessary. They even draw up supervillain graphics for them. https://www.crowdstrike.com/adversaries/arcane-kitten/

This is wild. Ethereal Panda? Labyrinth Chollima?!

Why are we modelling threat actors/"adversaries" as a video game bestiary? Or meteorological phenomena in the case of MS?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#117
post #32

They should look at upgrading their Entra ID plan to P2 in order to protect against these attacks.

And all things considered, an AI security assistant like Copilot might be a good investment too, if they lack highly skilled front line security staff. Not to mention, AI generated automated playbooks in Sentinel to automatically apply Zero Trust principles! I also wonder if they had upgraded all of their Subscriptions to Defender for Cloud CSPM Tier 2 in order to use the premium Cloud Security Attack Graph explorer,…

Lost my sanity there for a moment before realizing what you did. Good job!

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#118
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

Not to downplay the severity but honestly, every breach I read about seems “serious” but very rarely does anything of consequence happen with these events. Azure was owned pretty hard a while back, very little was ever heard of it again. Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?

It makes the news when an entity like Microsoft gets cracked, but when their users get robbed or otherwise hurt as a consequence it will hardly make the news. You not knowing of the consequences doesn't mean they don't exist.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#119
Seriously? This reads like a joke. They brute forced some tenant test systems.

Fine, I bet the password was Password123!, but then "they used account's permissions" to access various corporate emails. How is that even possible? What does it mean "they used the account's permissions"? Are you telling me there was no privilege separation between a tenant test environment and the internal domain? That the tenant system was not in its own isolated network? This is absolutely insane. Whenever I read stuff like that I wonder if some junior IT employee didn't just buy a new home for cash few months ago. I'm all for "don't look for malice where incompetence is a sufficient explanation", but that's just a little too much incompetence to be believable.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#120
post #114
post #108

Earlier quoted context omitted.

Yes, and I think most people would consider it a vulnerability if an authentication system doesn't rate-limit or otherwise slow/stop "password spray" attacks.

You can rate limit individual users but password spray attacks use a large number of accounts to remain undetected in a authentication system used by an even more users.

We are getting 10000x times the number of wrong passwords than average, I'm sure it's nothing to worry about.
Post reply on HN