Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

121–130 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#121
post #116

Earlier quoted context omitted.

Definitely agree that Crowdstrikes naming veers past what is necessary. They even draw up supervillain graphics for them. https://www.crowdstrike.com/adversaries/arcane-kitten/

This is wild. Ethereal Panda? Labyrinth Chollima?! Why are we modelling threat actors/"adversaries" as a video game bestiary? Or meteorological phenomena in the case of MS?

Why not?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#122
post #58

How did they pivot from a test tenant to corporate email access? That's the most concerning fact that they just glossed over.

You know, they pivoted. Non-production tenant PIVOT Satya’s email inbox. Like that.

Pivot! PIVOT!!! https://youtu.be/njgfomF51fg

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#123

Earlier quoted context omitted.

Not to downplay the severity but honestly, every breach I read about seems “serious” but very rarely does anything of consequence happen with these events. Azure was owned pretty hard a while back, very little was ever heard of it again. Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?

It makes the news when an entity like Microsoft gets cracked, but when their users get robbed or otherwise hurt as a consequence it will hardly make the news. You not knowing of the consequences doesn't mean they don't exist.

The company will be making record profits next year. There maybe consequences but nothing consequential in the grand scheme of things.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#124
post #114

Earlier quoted context omitted.

You can rate limit individual users but password spray attacks use a large number of accounts to remain undetected in a authentication system used by an even more users.

We are getting 10000x times the number of wrong passwords than average, I'm sure it's nothing to worry about.

It was a legacy test system connected to a production system so it doesn't count. Obviously. /s

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#126
post #71

Earlier quoted context omitted.

1. Password spray 2. Access non-prod environment 3. ??? 4. "Look at me, look at me, I am the CEO now."

I reflexively read #4 to the tune of Flobots - Handlebars

Reflexively? That song is almost 20 years old! (oh god now I feel old too)

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#127
post #98

>Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium How do they identify those groups?

They are just making it up.

Security people seems to be of the militaristic type ofent, so I guess they add a slive of war mongering to it to to play ball.

Iran, North Korea and what not. Very convenient since it is not falsifiable in practice.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#128

Earlier quoted context omitted.

It makes the news when an entity like Microsoft gets cracked, but when their users get robbed or otherwise hurt as a consequence it will hardly make the news. You not knowing of the consequences doesn't mean they don't exist.

The company will be making record profits next year. There maybe consequences but nothing consequential in the grand scheme of things.

Turns out there's more possible consequences than company profits being impacted.

Users are more than just things you milk for cash, they're people that trusted you and your product.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#129

Earlier quoted context omitted.

It makes the news when an entity like Microsoft gets cracked, but when their users get robbed or otherwise hurt as a consequence it will hardly make the news. You not knowing of the consequences doesn't mean they don't exist.

The company will be making record profits next year. There maybe consequences but nothing consequential in the grand scheme of things.

I find this reply incredibly cynical.

GP is clearly saying "this is important because small people will get hurt invisibly" and your hot take is that them being exploited isn't going to impact Microsoft's bottom line, so this isn't newsworthy?

This is vice-signaling.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#130

Earlier quoted context omitted.

I like this bit ... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents. Yeah, at least they make a very small percentage of all Microsoft employees I guess

Also this: "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems." So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.

They mean root access on the production email servers, not access to individual email accounts.
Post reply on HN