Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

41–50 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#41
post #26
post #25

Earlier quoted context omitted.

I agree around teams and outlook, but what is the alternative? Google? AWS? Self host? Honest question, because the way enterprise tends to work, they want to offload the responsibility to a third party so When information does leak or get hacked, they can blame someone else.

> but what is the alternative? Google? AWS? Self host? I mean, given this was possible: > used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts pretty much anything is going to be better than letting Microsoft host your email/corporate data

[deleted]

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#42
post #38

Earlier quoted context omitted.

> The U.S. Federal Bureau of Investigation (FBI), U.S. Cybersecurity & Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), Polish Military Counterintelligence Service (SKW), CERT Polska (CERT.PL), and the UK’s National Cyber Security Centre (NCSC) assess Russian Foreign Intelligence Service (SVR) cyber actors—also known as Advanced Persistent Threat 29 (APT 29), the Dukes, CozyBear, and NOBELI…

Im guessing that's like saying they are hired by the Russian equivalent of the CIA and following direct orders from top Russian officials?

While the CIA is a US foreign intelligence agency, I'd hesitate to call them equivalent. Hired by as in, employees of, Russian intelligence? Unless my link is inaccurate, yes.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#43
post #35

Earlier quoted context omitted.

trading MSFT doesn't cease when the NASDAQ closing bell rings

Still, it seems to be the custom.

if you're a retail investor maybe

there's thousands of ways to get exposure to MSFT one way or the other beyond the primary market

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#44
post #2

Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.

> It’s ok to call them countries, hackers, and intrusions. It's not if you want to do business in that country. Or if you annoy allies of that country (accusing certain countries might get senators breathing down your neck!). You are accusing a government of committing a crime, or at least a wildly unethical behavior. Those are huge charges. To your point, I wish they could be more direct, but... > Microsoft got hack…

It is government sponsored. It says in the article.

>Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#45

Did they release this late on a friday to downplay the scope of the attack? If they had top leadership accounts and service accounts hacked just by password protection sounds like a major security fubar.

Releasing news after the stock market is closed gives traders a chance to digest the news before trading begins the next day. (Which doesn't explain why it's on a Friday.)

It could be sort of neat if there was a convention for all news agencies and press rooms to queue up all their stories and release them after the end of the business day.

Why advantage parties that can process in less than 12 hours? Rushing analysis just makes it worse.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#46
post #32

They should look at upgrading their Entra ID plan to P2 in order to protect against these attacks.

And all things considered, an AI security assistant like Copilot might be a good investment too, if they lack highly skilled front line security staff. Not to mention, AI generated automated playbooks in Sentinel to automatically apply Zero Trust principles!

I also wonder if they had upgraded all of their Subscriptions to Defender for Cloud CSPM Tier 2 in order to use the premium Cloud Security Attack Graph explorer, and then enabled Workload protections, this tragedy could have been averted.

It’s going to take an army of motivated sales engineers to protect against these new cybernetic attacks by augmented warfighters.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#48
"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz."

I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#49
I wonder which mail client the execs were using. If Outlook, their messages would be already harvested by 700+ companies[0] and another leak wouldn't be an issue.

[0] https://news.ycombinator.com/item?id=38441710

[0] https://news.ycombinator.com/item?id=38953618

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#50
post #39
post #26

Earlier quoted context omitted.

> but what is the alternative? Google? AWS? Self host? I mean, given this was possible: > used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts pretty much anything is going to be better than letting Microsoft host your email/corporate data

[flagged]

Got a reference for that?

To be clear: I've never heard of any such thing. I happen to work for Google, but I'm open the possibility that this happened and I didn't hear about it.

Post reply on HN