Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

51–60 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#51
post #40

> Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts [...] > The attack was not the result of a vulnerability in Microsoft products or services. Hmm...

They mention it was a password spray guess.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#52

Interesting that they seem to suggest that applying security is now more important than avoiding service disruptions. This may be the hopeful dawn of a new era.

I work in the security space. It is the dawn of an era where all the makers are stamped down under the boot ridiculous security theater via regulation for "security" and "protection" and the current interests become entrenched to ensure a couple of guys in their garage can no longer upset the behemoths of the tech space.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#53
“it was Russia, they went thata way!”

this presents no proof, but I’ve read lots of krebs security proof on other exploits and I think it is all very weak

nothing is stopping anybody here from putting breadcrumbs in a payload to point the finger at North Korea or a former Soviet state

This is kind of a silly standard that allows hackers to operate with impunity and companies to avoid accountability and the fbi from not bothering

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#54
post #40

> Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts [...] > The attack was not the result of a vulnerability in Microsoft products or services. Hmm...

They mention it was a password spray guess.

I'm guessing they don't know what a password spray is?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#55
post #25
post #22

Earlier quoted context omitted.

yes, at least 1% of their users which is a very large number > To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems. senior executive's email accounts aren't production? having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disas…

I agree around teams and outlook, but what is the alternative? Google? AWS? Self host? Honest question, because the way enterprise tends to work, they want to offload the responsibility to a third party so When information does leak or get hacked, they can blame someone else.

Google or self-host.

With self-hosting you get to use thing now considered legacy (e.g., IMAP servers), but I definitely have seen them working for organisations with thousands of employees. You’ll need staff to support it, too, but at some scale it will none be more expensive than cloud services. Yet, you’ll have more control over it.

OTOH, some things will definitely be less feature-rich, for example, on-prem Sharepoint (not that I recommend using it) may not live up to the expectations of users familiar with the online version.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#56
post #50
post #39

Earlier quoted context omitted.

[flagged]

Got a reference for that? To be clear: I've never heard of any such thing. I happen to work for Google, but I'm open the possibility that this happened and I didn't hear about it.

They probably confuse it with Russians hacking Yahoo and having access to user account admin interface: https://www.csoonline.com/article/560623/inside-the-russian-...

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#57

Earlier quoted context omitted.

The naming framework for these groups isn't even consistent, with every vendor having their own scheme. Midnight Animal to one vendor is Dancing Bear to another and known by Wet Cat to yet another. They all sound like bad translations to bargain-bin porno movies.

I’m not aware of another company that uses a naming framework.

Crowdstrike. FireEye.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#59

Did they release this late on a friday to downplay the scope of the attack? If they had top leadership accounts and service accounts hacked just by password protection sounds like a major security fubar.

Releasing news after the stock market is closed gives traders a chance to digest the news before trading begins the next day. (Which doesn't explain why it's on a Friday.)

traditionally, the weekend gave even more time to sleep on it. modern near 24/7 trading makes that less of thing. back when the traders went home, there was a cooling off period. just like the circuit breakers to stop trading on big loss days to get the humans to stop and think for a second/minute/overnight. the high frequency trading doesn't have these emotions to cool down from, so it's still something that seems to be done on tradition now.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#60

“it was Russia, they went thata way!” this presents no proof, but I’ve read lots of krebs security proof on other exploits and I think it is all very weak nothing is stopping anybody here from putting breadcrumbs in a payload to point the finger at North Korea or a former Soviet state This is kind of a silly standard that allows hackers to operate with impunity and companies to avoid accountability and the fbi from n…

Depends. If the breadcrumbs are key material which correlates to other known incidents from the same group, or exclusive tooling, or C2 infrastructure, then there is definitely something stopping them from putting breadcrumbs there. They'd have to hack the other group first in order to do so.

I agree with you that seeing evidence would be nice, but I understand that there is the possibility that evidence supporting the claim exists and at the same time cannot be released to the public.

Post reply on HN