Microsoft: Hackers had access to internal mails

Discussion in 'other security issues & news' started by summerheat, Jan 20, 2024.

  1. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,259
    Once again Microsft was a victim of of a cyber attack. A hacker group named Midnight Blizzard (also known as Nobelium, Cozy Bear or APT29) had access to an internal account:

    According to Microsoft the "attack was not the result of a vulnerability in Microsoft products or services". However, it is obvious that a number of things went wrong:
    - Obviously that test account was secured only by a weak password.
    - Additionally it seems that they didn't use 2FA.
    - Third, that test account had extensive permissions that allowed access to real internal accounts of even their senior leadership team, ironically among them some of their cybersecurity team.

    This again shows that security is nothing you should rely upon when using Microsoft products.
     
  2. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,187
    Location:
    USA
    Yet another reason to not use the new Outlook which gives them the credentials for ALL of your email accounts.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    It is indeed weird that this attack was successful, to say the least. Why wasn't 2FA enabled, and why wasn't it noticed that someone logged into all of these other email accounts? So basically email security on MS's network was non existant. Weren't they using MS Defender for email security? :eek:

    https://www.microsoft.com/en-za/security/business/siem-and-xdr/microsoft-defender-office-365
     
  4. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,259
    Yep - and now add to this the new Outlook vulnerability that allows an attacker to get your NTLM v2 hashed passwords via a calendar invitation. It's a disaster.
     
  5. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    9,187
    Location:
    USA
    Wow, unbelievable. Thanks for sharing.
     
  6. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,259
  7. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
    "The Russian state-sponsored hackers did so after stealing corporate emails from Microsoft back in January. But so far, no customer-facing systems have been compromised...

    The company didn't specify if any source code was exfiltrated. But the hackers have been using information found in the stolen corporate emails to break into the systems of Microsoft and its customers. This has included trying to guess login passwords..."

    https://www.pcmag.com/news/microsoft-russian-hackers-accessed-company-source-code
     
  8. hawki

    hawki Registered Member

    Joined:
    Dec 17, 2008
    Posts:
    6,130
    Location:
    DC Metro Area
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    So from what I understood, MS was hacked again as result from the first hack, and perhaps even source code was stolen? And MS wants us to take them seriously when it comes to Windows Defender on both home user and corporate machines? While they can't even secure their own systems? :confused:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.