Earlier quoted context omitted.
I agree around teams and outlook, but what is the alternative? Google? AWS? Self host? Honest question, because the way enterprise tends to work, they want to offload the responsibility to a third party so When information does leak or get hacked, they can blame someone else.
> but what is the alternative? Google? AWS? Self host? I mean, given this was possible: > used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts pretty much anything is going to be better than letting Microsoft host your email/corporate data
Microsoft actions following attack by nation state actor Midnight Blizzard
41–50 of 204 posts
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#42Earlier quoted context omitted.
> The U.S. Federal Bureau of Investigation (FBI), U.S. Cybersecurity & Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), Polish Military Counterintelligence Service (SKW), CERT Polska (CERT.PL), and the UK’s National Cyber Security Centre (NCSC) assess Russian Foreign Intelligence Service (SVR) cyber actors—also known as Advanced Persistent Threat 29 (APT 29), the Dukes, CozyBear, and NOBELI…
Im guessing that's like saying they are hired by the Russian equivalent of the CIA and following direct orders from top Russian officials?
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#43Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#44Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.
> It’s ok to call them countries, hackers, and intrusions. It's not if you want to do business in that country. Or if you annoy allies of that country (accusing certain countries might get senators breathing down your neck!). You are accusing a government of committing a crime, or at least a wildly unethical behavior. Those are huge charges. To your point, I wish they could be more direct, but... > Microsoft got hack…
>Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#45Did they release this late on a friday to downplay the scope of the attack? If they had top leadership accounts and service accounts hacked just by password protection sounds like a major security fubar.
Releasing news after the stock market is closed gives traders a chance to digest the news before trading begins the next day. (Which doesn't explain why it's on a Friday.)
Why advantage parties that can process in less than 12 hours? Rushing analysis just makes it worse.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#46They should look at upgrading their Entra ID plan to P2 in order to protect against these attacks.
I also wonder if they had upgraded all of their Subscriptions to Defender for Cloud CSPM Tier 2 in order to use the premium Cloud Security Attack Graph explorer, and then enabled Workload protections, this tragedy could have been averted.
It’s going to take an army of motivated sales engineers to protect against these new cybernetic attacks by augmented warfighters.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#47Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#48I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#49Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#50Earlier quoted context omitted.
> but what is the alternative? Google? AWS? Self host? I mean, given this was possible: > used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts pretty much anything is going to be better than letting Microsoft host your email/corporate data
[flagged]
To be clear: I've never heard of any such thing. I happen to work for Google, but I'm open the possibility that this happened and I didn't hear about it.