Earlier quoted context omitted.
yes, at least 1% of their users which is a very large number > To date, there is no evidence that the threat actor had any access to customer environments, *production systems*, source code, or AI systems. senior executive's email accounts aren't production? having every western company use the garbage that are Microsoft's hosted products (notably Teams and Outlook) is a national security issue that's a massive disas…
This kind of attack can happen on any tech stack where bad passwords have ever been allowed. The dunking is obviously fun, but the fact that the underlying technology happened to be Microsoft’s is largely irrelevant.
Microsoft actions following attack by nation state actor Midnight Blizzard
91–100 of 204 posts
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#92Earlier quoted context omitted.
As we've seen, many of the cybersecurity teams have been pwned, so a large part of the breadcrumbs they'd pattern match are already out there. Additionally, if security is poor enough, there can be more than one hacker into a system, which is another way they could accumulate breadcrumbs. This has precedent - there has been malware that uninstalls other malware.
Many? I'm only aware of the Equation group, believed to be the NSA, whose extremely powerful tools were made public. What other threat actor's internals (and I mean more then chat logs) have been made public?
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#93Why does the data security industry seem to be so into obfuscated jargon? It’s like a new industry microcosm corporatespeak. It’s ok to call them countries, hackers, and intrusions. Microsoft got hacked by Russian government hackers.
At least for the "Midnight Blizzard" part of the title, it's the result of a naming framework [0] for threat actors that Microsoft has been using since April 2023. I agree it sounds weird. [0] https://learn.microsoft.com/en-us/microsoft-365/security/int...
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#94"We were pwned by the Russians (again) and they were reading all of Satya's emails, but it's okay, they were just looking for shout-outs to post in their interoffice Telegram channel for the lulz." I understand that the company has to minimize every breach but this frankly looks a lot more serious than Microsoft suggests here.
Microsoft is pretty learning resistant lately. Always prioritize the spamming customers, I guess?
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#95Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#96>Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts I have so many questions from this sentence alone. What did they password spray? Microsoft's internal identity provider? Was the non-prod system inte…
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#97>Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts I have so many questions from this sentence alone. What did they password spray? Microsoft's internal identity provider? Was the non-prod system inte…
Indeed. How can they not be mandating MFA?
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#98How do they identify those groups?
Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#99Re: Microsoft actions following attack by nation state actor Midnight Blizzard
#100Earlier quoted context omitted.
I love how they emphasize only few were exposed. Like just a few, only our senior staff and cybersecurity team... I mean -- they aren't lying, but... Wow
Isn't the rule "if you are being targeted directly, lose all hope"?