ZeroHour
Ars Technica · Securitypublished ()ingested 1

Microsoft network breached through password-spraying by Russia

lowData breachimportance 45
Tagsbreach
Full article287 words · extracted from arstechnica.com · click to collapse

Furthermore, this “legacy non-production test tenant account” was somehow configured so that Midnight Blizzard could pivot and gain access to some of the company’s most senior and sensitive employee accounts.

As Steve Bellovin, a computer science professor and affiliate law professor at Columbia University with decades of experience in cybersecurity, wrote on Mastodon:

While Microsoft said that it wasn’t aware of any evidence that Midnight Blizzard gained access to customer environments, production systems, source code, or AI systems, some researchers voiced doubts, particularly about whether the Microsoft 365 service might be or have been susceptible to similar attack techniques. One of the researchers was Kevin Beaumont, who has had a long cybersecurity career that has included a stint working for Microsoft. On LinkedIn, he wrote:

Microsoft staff use Microsoft 365 for email. SEC filings and blogs with no details on Friday night are great… but they’re going to have to be followed with actual detail. The age of Microsoft doing tents, incident code words, CELA’ing things and pretending MSTIC sees everything (threat actors have Macs too) are over — they need to do radical technical and cultural transformation to retain trust.

CELA is short for Corporate, External, and Legal Affairs, a group inside Microsoft that helps draft disclosures. MSTIC stands for the Microsoft Threat Intelligence Center.

A Microsoft representative said the company declined to answer questions, including whether basic security practices were followed.

The breach is reminiscent of one that hit Microsoft last year when China-state hackers, tracked as Storm-0558, broke into Microsoft’s network. Over the next month, the group accessed Azure and Exchange accounts of multiple customers, several of which belonged to the US Departments of State and Commerce.

As I reported in September:

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2024/01/microsoft-network-breached-through-password-spraying-by-russian-state-hackers/