Live data from Hacker News

Microsoft actions following attack by nation state actor Midnight Blizzard

msrc.microsoft.com

71–80 of 204 posts

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#71

Earlier quoted context omitted.

You know, they pivoted. Non-production tenant PIVOT Satya’s email inbox. Like that.

1. Password spray 2. Access non-prod environment 3. ??? 4. "Look at me, look at me, I am the CEO now."

I reflexively read #4 to the tune of Flobots - Handlebars

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#73
post #61
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

I love how they emphasize only few were exposed. Like just a few, only our senior staff and cybersecurity team... I mean -- they aren't lying, but... Wow

"very small percentage"

1% of 238,000 employees is a "very small percentage" and still 2,380 employees. Insight into certain operational information and potentially undisclosed/unpatched zero days could be monumentally valuable to a nation state actor.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#74
post #32

They should look at upgrading their Entra ID plan to P2 in order to protect against these attacks.

I wonder if they switched from user-based MFA to Conditional Access MFA yet, maybe they forgot to enable alerting for non-interactive logins. Maybe they forgot to update the Log Analytics Agent to the Azure Monitoring Agent. /s

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#76

What does the title mean?

I had to read the title multiple times but couldn't make sense of what is exactly happening.

Why is this happening to English?

The other day, there was a story about an airplane window that got melt and many native speakers couldn't make sense of what the title of the story meant?

In that case too, as a non native speaker of English, I blamed myself first for not understanding the language well enough.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#77

Um. Why does "a legacy non-production test tenant account" have "permissions" for "email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions"?

The usual reason include: oversight; mistake; incompetence.

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#78
post #48

"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.

The Friday evening blog post also seems designed to brush this under the rug.

"We will act immediately to apply our current security standards to Microsoft-owned legacy systems and internal business processes"

In other words: Microsoft will adopt their own security standards. Curious whether their SOC reports mention these are optional?

Re: Microsoft actions following attack by nation state actor Midnight Blizzard

#79
post #60

“it was Russia, they went thata way!” this presents no proof, but I’ve read lots of krebs security proof on other exploits and I think it is all very weak nothing is stopping anybody here from putting breadcrumbs in a payload to point the finger at North Korea or a former Soviet state This is kind of a silly standard that allows hackers to operate with impunity and companies to avoid accountability and the fbi from n…

Depends. If the breadcrumbs are key material which correlates to other known incidents from the same group, or exclusive tooling, or C2 infrastructure, then there is definitely something stopping them from putting breadcrumbs there. They'd have to hack the other group first in order to do so. I agree with you that seeing evidence would be nice, but I understand that there is the possibility that evidence supporting t…

As we've seen, many of the cybersecurity teams have been pwned, so a large part of the breadcrumbs they'd pattern match are already out there. Additionally, if security is poor enough, there can be more than one hacker into a system, which is another way they could accumulate breadcrumbs. This has precedent - there has been malware that uninstalls other malware.
Post reply on HN