'Midnight Blizzard' Breached HPE Email Months Before Microsoft Hack
ID: 476ac927-4e63-5807-b0bf-d6deadb0a229
STIX ID: report--476ac927-4e63-5807-b0bf-d6deadb0a229
Feed Name: Dark Reading
Threat Score
The report details confirmed intrusions by Russia-linked threat actor Midnight Blizzard (APT29/Nobelium) that accessed and exfiltrated email and limited SharePoint data from Hewlett-Packard Enterprise in May 2023 and from Microsoft after a November 2023 breach; it highlights the actor's use of password-spray attacks, exploitation of known product vulnerabilities (including CVE-2023-42793 in JetBrains TeamCity), and ties to prior large-scale supply-chain activity such as SolarWinds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
