Microsoft sheds some light on Russian email heist – and how to learn from Redmond's mistakes
ID: 79353d64-e3c1-55f6-8355-3845bf35f684
STIX ID: report--79353d64-e3c1-55f6-8355-3845bf35f684
Feed Name: The Register (Security)
Microsoft disclosed that Kremlin-backed espionage group Midnight Blizzard (APT29/Cozy Bear) used password-spray attacks to breach a legacy, non-production test tenant that lacked multi-factor authentication, then leveraged a compromised legacy OAuth application to access and steal emails and files from corporate executives and staff; attackers also used residential broadband proxies to blend their traffic, prompting Microsoft to accelerate MFA and legacy-system remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
