CISA emergency directive tells agencies to fix credentials after Microsoft breach
ID: 7c4a85d8-afab-5eac-8fdb-4693dc42cda9
STIX ID: report--7c4a85d8-afab-5eac-8fdb-4693dc42cda9
Feed Name: CyberScoop
CISA issued an emergency directive after Microsoft disclosed that the Russian-linked APT group Midnight Blizzard (aka Cozy Bear / APT29) compromised Microsoft corporate email accounts and exfiltrated agency correspondence, including authentication secrets. Affected federal civilian agencies were ordered to reset credentials, identify impacted emails, and report remediation actions as the threat actor increased password-spray activity and used exfiltrated authentication details to attempt further access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
