Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

31–40 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#31
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

Woah. Easy there. It sounds like you're trying to start a flamewar by singling out Russia. Don't you know that every country does this?! Please preface any accusations against Russia with paragraphs of anti-Western invective. /s

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#33

Did they release this late on a friday to downplay the scope of the attack? If they had top leadership accounts and service accounts hacked just by password protection sounds like a major security fubar.

Releasing news after the stock market is closed gives traders a chance to digest the news before trading begins the next day.

(Which doesn't explain why it's on a Friday.)

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#34
post #22

Earlier quoted context omitted.

Seems weird to word it as “a very small percentage” instead of “a very small number” unless the number was a little bigger than they want to admit.

yes, at least 1% of their users which is a very large number > To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems. senior executive's email accounts aren't production? having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disas…

The denominator is "Microsoft corporate email accounts." I interpret that as email accounts of the Microsoft organization (management, employees, and so on), but not customers.

It's pretty embarrassing and not very reassuring that they themselves got owned, but they wanted to tell their customers that they didn't.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#35

Did they release this late on a friday to downplay the scope of the attack? If they had top leadership accounts and service accounts hacked just by password protection sounds like a major security fubar.

Releasing news after the stock market is closed gives traders a chance to digest the news before trading begins the next day. (Which doesn't explain why it's on a Friday.)

trading MSFT doesn't cease when the NASDAQ closing bell rings

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#36
post #14
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

Russia hacks, but so do China, North Korea, Iran and Ukraine. They all have bagged large targets. It could be any of them but could be someone else as well.

As does UK and the USA. Maybe it's Microsoft hacking it self; GPT style.

If so, hello Skynet.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#37
post #35

Earlier quoted context omitted.

Releasing news after the stock market is closed gives traders a chance to digest the news before trading begins the next day. (Which doesn't explain why it's on a Friday.)

trading MSFT doesn't cease when the NASDAQ closing bell rings

Still, it seems to be the custom.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#38
post #7

Earlier quoted context omitted.

Your summary is also ambiguous. Were they hacked by the Russian CIA equivalent? Were they hacked by people funded by the Russian government? Were they hacked by people funded by senior government officials? I think it's possible that the truth is a little murky, and capturing that ambiguity is actually clearer than trying to wave it away

> The U.S. Federal Bureau of Investigation (FBI), U.S. Cybersecurity & Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), Polish Military Counterintelligence Service (SKW), CERT Polska (CERT.PL), and the UK’s National Cyber Security Centre (NCSC) assess Russian Foreign Intelligence Service (SVR) cyber actors—also known as Advanced Persistent Threat 29 (APT 29), the Dukes, CozyBear, and NOBELI…

Im guessing that's like saying they are hired by the Russian equivalent of the CIA and following direct orders from top Russian officials?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#39
post #26
post #25

Earlier quoted context omitted.

I agree around teams and outlook, but what is the alternative? Google? AWS? Self host? Honest question, because the way enterprise tends to work, they want to offload the responsibility to a third party so When information does leak or get hacked, they can blame someone else.

> but what is the alternative? Google? AWS? Self host? I mean, given this was possible: > used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts pretty much anything is going to be better than letting Microsoft host your email/corporate data

[flagged]

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#40
> Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts [...]

> The attack was not the result of a vulnerability in Microsoft products or services.

Hmm...

Post reply on HN