logo

Microsoft critics accuse the firm of ‘negligence’ in latest breach

ID: 206a4798-1ec9-5290-8b8f-3ebcd24ff8be

STIX ID: report--206a4798-1ec9-5290-8b8f-3ebcd24ff8be

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2024-01-24

Date Updated: 2026-04-21

Author: mbracken

...
...

Microsoft disclosed that the espionage group Cozy Bear (believed to be tied to Russia's SVR) breached a legacy non-production test tenant using a password-spraying attack, pivoted into Microsoft’s corporate network, and accessed emails of senior executives — including cybersecurity and legal staff. Critics say the incident reflects poor security hygiene (notably lack of required multi-factor authentication), could expose Microsoft’s investigative tradecraft and knowledge of unpatched vulnerabilities, and raises questions about the company’s security posture despite Microsoft stating there is no evidence of customer or product impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.