> Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts [...] > The attack was not the result of a vulnerability in Microsoft products or services. Hmm...
Microsoft actions following attack by nation state actor Midnight Blizzard
51–60 of 204 posts
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#52Interesting that they seem to suggest that applying security is now more important than avoiding service disruptions. This may be the hopeful dawn of a new era.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#53this presents no proof, but I’ve read lots of krebs security proof on other exploits and I think it is all very weak
nothing is stopping anybody here from putting breadcrumbs in a payload to point the finger at North Korea or a former Soviet state
This is kind of a silly standard that allows hackers to operate with impunity and companies to avoid accountability and the fbi from not bothering
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#54> Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts [...] > The attack was not the result of a vulnerability in Microsoft products or services. Hmm...
They mention it was a password spray guess.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#55Earlier quoted context omitted.
yes, at least 1% of their users which is a very large number > To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems. senior executive's email accounts aren't production? having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disas…
I agree around teams and outlook, but what is the alternative? Google? AWS? Self host? Honest question, because the way enterprise tends to work, they want to offload the responsibility to a third party so When information does leak or get hacked, they can blame someone else.
With self-hosting you get to use thing now considered legacy (e.g., IMAP servers), but I definitely have seen them working for organisations with thousands of employees. You’ll need staff to support it, too, but at some scale it will none be more expensive than cloud services. Yet, you’ll have more control over it.
OTOH, some things will definitely be less feature-rich, for example, on-prem Sharepoint (not that I recommend using it) may not live up to the expectations of users familiar with the online version.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#56Earlier quoted context omitted.
[flagged]
Got a reference for that? To be clear: I've never heard of any such thing. I happen to work for Google, but I'm open the possibility that this happened and I didn't hear about it.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#57Earlier quoted context omitted.
The naming framework for these groups isn't even consistent, with every vendor having their own scheme. Midnight Animal to one vendor is Dancing Bear to another and known by Wet Cat to yet another. They all sound like bad translations to bargain-bin porno movies.
I’m not aware of another company that uses a naming framework.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#58That's the most concerning fact that they just glossed over.
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#59Did they release this late on a friday to downplay the scope of the attack? If they had top leadership accounts and service accounts hacked just by password protection sounds like a major security fubar.
Releasing news after the stock market is closed gives traders a chance to digest the news before trading begins the next day. (Which doesn't explain why it's on a Friday.)
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#60“it was Russia, they went thata way!” this presents no proof, but I’ve read lots of krebs security proof on other exploits and I think it is all very weak nothing is stopping anybody here from putting breadcrumbs in a payload to point the finger at North Korea or a former Soviet state This is kind of a silly standard that allows hackers to operate with impunity and companies to avoid accountability and the fbi from n…
I agree with you that seeing evidence would be nice, but I understand that there is the possibility that evidence supporting the claim exists and at the same time cannot be released to the public.