Microsoft Shares New Guidance in Wake of 'Midnight Blizzard' Cyberattack
ID: b1024b03-644b-53da-b7d5-f2cec71708d4
STIX ID: report--b1024b03-644b-53da-b7d5-f2cec71708d4
Feed Name: Dark Reading
Microsoft disclosed that the nation-state group Midnight Blizzard (Cozy Bear/SVR) accessed Microsoft corporate email by password-spraying a legacy test account, leveraging a compromised legacy OAuth app and creating malicious OAuth applications to obtain non-expiring tokens and exfiltrate emails and attachments; Microsoft released guidance to detect and mitigate such OAuth abuse by auditing high-privilege and non-human identities, reviewing ApplicationImpersonation privileges, and using anomaly detection and conditional access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
