Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

131–140 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#131
post #98

>Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium How do they identify those groups?

From the artifacts they leave behind after the attack, broadly speaking.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#132

Earlier quoted context omitted.

The company will be making record profits next year. There maybe consequences but nothing consequential in the grand scheme of things.

I find this reply incredibly cynical. GP is clearly saying "this is important because small people will get hurt invisibly" and your hot take is that them being exploited isn't going to impact Microsoft's bottom line, so this isn't newsworthy? This is vice-signaling.

Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents. The investigation indicates they were initially targeting email accounts for information related to Midnight Blizzard itself. We are in the process of notifying employees whose email was accessed.

It says nothing about users being compromised.

This is why they won’t do anything about it though ? Do you understand how it works ?

They’re not going to do anything about the consequences for the users until it impacts their profits.

Name one person who is done with Microsoft after this?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#133
post #57

Earlier quoted context omitted.

Crowdstrike. FireEye.

Definitely agree that Crowdstrikes naming veers past what is necessary. They even draw up supervillain graphics for them. https://www.crowdstrike.com/adversaries/arcane-kitten/

This is really cool and incredibly stupid.

Like, who is this made to appeal to? Is this meant to make corporate executive browsing for cybersecurity solutions feel like they're in a spy movie?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#135

Earlier quoted context omitted.

I find this reply incredibly cynical. GP is clearly saying "this is important because small people will get hurt invisibly" and your hot take is that them being exploited isn't going to impact Microsoft's bottom line, so this isn't newsworthy? This is vice-signaling.

Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attac…

I think the confusion lies between the terms "consequences" and "consequences for Microsoft". There won't be consequences _for Microsoft_ but there will be consequences for regular people. Saying there won't be consequences full stop implies you don't consider the damage to regular people as worthy of discussion or consideration

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#137

Earlier quoted context omitted.

I like this bit ... a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents. Yeah, at least they make a very small percentage of all Microsoft employees I guess

Also this: "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems." So email accounts of senior leadership and employees in cybersecurity are apparently not production systems.

No, they are not. Production systems are the systems that are producing money. If they stop running for an hour, it directly costs the company money through SLA penalties, etc. If the internal email server goes down for an hour, it might cause some employee productivity loss, depending on the timing.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#138
post #134

Why do they say "nation state actor", isn't "state actor" the correct term? I thought Russia, like the UK and many other states, is a multinational state, including numerous languages and cultures.

I've always wondered why infosec people love this expression so much. Maybe "nation state" just sounds more impressive. Who cares what the state is composed of? Or is it "nation/state", one or the other?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#139
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

Is there any basis for this group being "nation-state" or are they just trying to make themselves seem less incompetent by inflating the attackers' reputation?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#140
post #102
post #44

Earlier quoted context omitted.

It is government sponsored. It says in the article. >Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium.

But how do they know that it's sponsored by Russia? They saw the paychecks?

They’ve been around for a while and identified by several governments.

“NOBELIUM is an advanced persistent threat group also known as APT29, which is publicly attributed to the Russian government and specifically to the Foreign Intelligence Service of the Russian Federation (SVR)”

https://blogs.blackberry.com/en/2023/03/nobelium-targets-eu-...

Post reply on HN