Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

21–30 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#21

Interesting that they seem to suggest that applying security is now more important than avoiding service disruptions. This may be the hopeful dawn of a new era.

It is indeed the beginning of a new AI related era. But why cloud services, Microsoft? There is already a new infrastructure on the way better suited for AI, called edge computing. I'm not talking about completely eliminating cloud services. But solely depending on these kind of services could lead to further problems later due to this topic (national security) is very serious for all of us.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#22
post #8

> access a very small percentage of Microsoft corporate email accounts Ok, so far so good. > including members of our senior leadership team Ahhh, so maybe the attackers were after the senior leadership team and therefore stopped at the "very small percentage".

Seems weird to word it as “a very small percentage” instead of “a very small number” unless the number was a little bigger than they want to admit.

yes, at least 1% of their users

which is a very large number

> To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems.

senior executive's email accounts aren't production?

having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disaster that's just waiting to happen

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#23

Earlier quoted context omitted.

At least for the "Midnight Blizzard" part of the title, it's the result of a naming framework [0] for threat actors that Microsoft has been using since April 2023. I agree it sounds weird. [0] https://learn.microsoft.com/en-us/microsoft-365/security/int...

The naming framework for these groups isn't even consistent, with every vendor having their own scheme. Midnight Animal to one vendor is Dancing Bear to another and known by Wet Cat to yet another. They all sound like bad translations to bargain-bin porno movies.

I’m not aware of another company that uses a naming framework.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#24
post #14
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

Russia hacks, but so do China, North Korea, Iran and Ukraine. They all have bagged large targets. It could be any of them but could be someone else as well.

[deleted]

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#25
post #22

Earlier quoted context omitted.

Seems weird to word it as “a very small percentage” instead of “a very small number” unless the number was a little bigger than they want to admit.

yes, at least 1% of their users which is a very large number > To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems. senior executive's email accounts aren't production? having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disas…

I agree around teams and outlook, but what is the alternative? Google? AWS? Self host? Honest question, because the way enterprise tends to work, they want to offload the responsibility to a third party so When information does leak or get hacked, they can blame someone else.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#26
post #25
post #22

Earlier quoted context omitted.

yes, at least 1% of their users which is a very large number > To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems. senior executive's email accounts aren't production? having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disas…

I agree around teams and outlook, but what is the alternative? Google? AWS? Self host? Honest question, because the way enterprise tends to work, they want to offload the responsibility to a third party so When information does leak or get hacked, they can blame someone else.

> but what is the alternative? Google? AWS? Self host?

I mean, given this was possible:

> used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts

pretty much anything is going to be better than letting Microsoft host your email/corporate data

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#27
Microsoft filed this late today with the SEC[1] just before they stopped accepting new filings for the day under their new Cybersecurity Incident disclosure rule[2]. FWIW, two other publicly traded companies disclosed[3] their breaches since the rule went into affect last month.

[1] https://www.sec.gov/Archives/edgar/data/789019/0001193125240...

[2] https://www.sec.gov/news/press-release/2023-139

[3] https://last10k.com/stock-screeners/cybersecurity

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#28
post #7
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

Your summary is also ambiguous. Were they hacked by the Russian CIA equivalent? Were they hacked by people funded by the Russian government? Were they hacked by people funded by senior government officials? I think it's possible that the truth is a little murky, and capturing that ambiguity is actually clearer than trying to wave it away

> The U.S. Federal Bureau of Investigation (FBI), U.S. Cybersecurity & Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), Polish Military Counterintelligence Service (SKW), CERT Polska (CERT.PL), and the UK’s National Cyber Security Centre (NCSC) assess Russian Foreign Intelligence Service (SVR) cyber actors—also known as Advanced Persistent Threat 29 (APT 29), the Dukes, CozyBear, and NOBELIUM/Midnight Blizzard

https://www.cisa.gov/topics/cyber-threats-and-advisories/adv...

So, they're "Russian Foreign Intelligence Service (SVR) cyber actors"

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#29
post #17

Earlier quoted context omitted.

> It’s ok to call them countries, hackers, and intrusions. It's not if you want to do business in that country. Or if you annoy allies of that country (accusing certain countries might get senators breathing down your neck!). You are accusing a government of committing a crime, or at least a wildly unethical behavior. Those are huge charges. To your point, I wish they could be more direct, but... > Microsoft got hack…

>> It is not known whether this hacking group is private, government sponsored, or government run. Coming from Russia, that's a distinction without a difference. Sure, private groups can 'freelance', but not without at least tacit permission from the FSB, GRU, and/or SVR (more accurately, cant freelance for long). Especially so for sch a high visibility target such as Microsoft. And when the RU govt isdues a denial,…

The distinction probably matters to a lot of people at the scale that Microsoft is operating at. They likely worked with some sort of MS US government liaison on the wording.

Operating with tacit approval is not the same as being a government entity. Even you admit there is a small chance that this group is not tacitly approved ("for long"). I mean yeah, we all know the score, but a it's really bad idea to levy heavy charges without knowing the answer 100%.

This statement does pretty heavily implicate the Russian Govt though, yeah :)

Post reply on HN