Site icon The AuroraTECH

Microsoft’s latest compromise may have been easily avoidable.

Advertisements

As Microsoft reveals “Midnight Blizzard” compromise, security pros suspect password spraying.

Late Friday, Microsoft revealed in a blog post that a Russian-backed group accessed the tech giant’s corporate email accounts. The compromise is a disconcerting one, according to some IT pros, given both the high privileges of those targeted and the method of access.

“This is not a great look for Microsoft, especially because it looks like, from the small amount of information they gave us, that this was a pretty simple kind of an attack, called a password spray, something that could be prevented by two-factor authentication, and Microsoft was not enforcing their own policies on certain systems,” Alex Stamos, chief trust officer at the cybersecurity company SentinelOne and former Facebook CSO, told CNBC this week.

A password-spraying attack is a type of brute force attack that uses educated guesses of likely credentials, thrown at multiple accounts in an organization.

What Microsoft shared:

Who is Midnight Blizzard? 

Not a late-night guilty pleasure at Dairy Queen, the group is perhaps best known for its compromise of the software company SolarWinds. In August of 2023, Microsoft wrote about how threat actors use compromised small-business accounts to create new domains that mimic tech-support entities. The group has also had a reputation for going after Active Directory.

Adam Meyers, SVP of counter adversary operations at the cybersecurity company CrowdStrike, knows the group as Cozy Bear, a crew considered responsible for multiple breaches over the last decade, said the VP, and likely acting on behalf of the Foreign Intelligence Service of the Russian Federation.

Meyers expressed skepticism about Microsoft’s claims that the compromise occurred on non-production systems.

“I don’t think there’s too many environments in the world where you’re going to put your senior executives, your cybersecurity team, and your legal team on a test environment,” Meyers said.

“Either they’re being disingenuous about the fact that this was a test environment, which is probably the best-case scenario for them. The worst-case scenario is that a legacy test environment is so deeply connected inside of the fabric of their infrastructure in their cloud, that a penetration of any aspect of the Microsoft Cloud can lead to a deeper intrusion into customer data or Microsoft’s data itself,” Meyers added.

Microsoft, which declined any interviews to address questions related to the non-production accounts, also faced a breach in September 2023 from China-based hackers, who, according to reports, extracted a cryptographic key from a Microsoft engineer’s corporate account.

Exit mobile version