Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

61–70 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#61
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

I love how they emphasize only few were exposed. Like just a few, only our senior staff and cybersecurity team... I mean -- they aren't lying, but... Wow

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#62
post #58

How did they pivot from a test tenant to corporate email access? That's the most concerning fact that they just glossed over.

You know, they pivoted.

Non-production tenant PIVOT Satya’s email inbox. Like that.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#64
post #57

Earlier quoted context omitted.

I’m not aware of another company that uses a naming framework.

Crowdstrike. FireEye.

Definitely agree that Crowdstrikes naming veers past what is necessary.

They even draw up supervillain graphics for them.

https://www.crowdstrike.com/adversaries/arcane-kitten/

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#65
>Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts

I have so many questions from this sentence alone. What did they password spray? Microsoft's internal identity provider? Was the non-prod system internet facing? Why isn't MFA enforced?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#66
post #35

Earlier quoted context omitted.

trading MSFT doesn't cease when the NASDAQ closing bell rings

Still, it seems to be the custom.

it's the custom because it's not just stock trading that they care about, it's brand/image, and weekends give the story time to disappear from the headlines, being replaced by new stories. Fewer people are paying attention to the news over the weekend.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#67
post #58

How did they pivot from a test tenant to corporate email access? That's the most concerning fact that they just glossed over.

You know, they pivoted. Non-production tenant PIVOT Satya’s email inbox. Like that.

1. Password spray

2. Access non-prod environment

3. ???

4. "Look at me, look at me, I am the CEO now."

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#68
post #63
post #58

How did they pivot from a test tenant to corporate email access? That's the most concerning fact that they just glossed over.

Just guessing but perhaps with a phishing attack on a Microsoft domain.

This is genuinely something I hadn't considered. A test tenant may have been in a more than ideal position to stage phishing attacks from. Hopefully this is the case, and not a more concerning lack of disclosure or shudder NSL situation.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#69
post #22

Earlier quoted context omitted.

Seems weird to word it as “a very small percentage” instead of “a very small number” unless the number was a little bigger than they want to admit.

yes, at least 1% of their users which is a very large number > To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems. senior executive's email accounts aren't production? having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disas…

This kind of attack can happen on any tech stack where bad passwords have ever been allowed. The dunking is obviously fun, but the fact that the underlying technology happened to be Microsoft’s is largely irrelevant.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#70
post #49

I wonder which mail client the execs were using. If Outlook, their messages would be already harvested by 700+ companies[0] and another leak wouldn't be an issue. [0] https://news.ycombinator.com/item?id=38441710 [0] https://news.ycombinator.com/item?id=38953618

Ever since Delve was introduced, Microsoft Outlook has felt weird to me
Post reply on HN