Earlier quoted context omitted.
Definitely agree that Crowdstrikes naming veers past what is necessary. They even draw up supervillain graphics for them. https://www.crowdstrike.com/adversaries/arcane-kitten/
This is wild. Ethereal Panda? Labyrinth Chollima?! Why are we modelling threat actors/"adversaries" as a video game bestiary? Or meteorological phenomena in the case of MS?
Microsoft actions following attack by nation state actor Midnight Blizzard
121–130 of 204 posts
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#122How did they pivot from a test tenant to corporate email access? That's the most concerning fact that they just glossed over.
You know, they pivoted. Non-production tenant PIVOT Satya’s email inbox. Like that.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#123Earlier quoted context omitted.
Not to downplay the severity but honestly, every breach I read about seems “serious” but very rarely does anything of consequence happen with these events. Azure was owned pretty hard a while back, very little was ever heard of it again. Is the drama of them appealing ? What might we expect to happen from this ? They’ve read Satya’s email ?
It makes the news when an entity like Microsoft gets cracked, but when their users get robbed or otherwise hurt as a consequence it will hardly make the news. You not knowing of the consequences doesn't mean they don't exist.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#124Earlier quoted context omitted.
You can rate limit individual users but password spray attacks use a large number of accounts to remain undetected in a authentication system used by an even more users.
We are getting 10000x times the number of wrong passwords than average, I'm sure it's nothing to worry about.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#125Just block all traffic from russia :)
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#126Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#127>Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium How do they identify those groups?
Security people seems to be of the militaristic type ofent, so I guess they add a slive of war mongering to it to to play ball.
Iran, North Korea and what not. Very convenient since it is not falsifiable in practice.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#128Earlier quoted context omitted.
It makes the news when an entity like Microsoft gets cracked, but when their users get robbed or otherwise hurt as a consequence it will hardly make the news. You not knowing of the consequences doesn't mean they don't exist.
The company will be making record profits next year. There maybe consequences but nothing consequential in the grand scheme of things.
Users are more than just things you milk for cash, they're people that trusted you and your product.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#129Earlier quoted context omitted.
It makes the news when an entity like Microsoft gets cracked, but when their users get robbed or otherwise hurt as a consequence it will hardly make the news. You not knowing of the consequences doesn't mean they don't exist.
The company will be making record profits next year. There maybe consequences but nothing consequential in the grand scheme of things.
GP is clearly saying "this is important because small people will get hurt invisibly" and your hot take is that them being exploited isn't going to impact Microsoft's bottom line, so this isn't newsworthy?
This is vice-signaling.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#130Earlier quoted context omitted.
I like this bit ... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents. Yeah, at least they make a very small percentage of all Microsoft employees I guess
Also this: "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems." So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.