logo

CISA orders agencies impacted by Microsoft hack to mitigate risks

ID: e86d7cb4-91fe-5e2d-92c0-d5428b28d7d1

STIX ID: report--e86d7cb4-91fe-5e2d-92c0-d5428b28d7d1

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-04-11

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA issued Emergency Directive 24-02 after Russian APT29 breached Microsoft corporate email in January, exfiltrating emails — including from U.S. federal agencies — and using stolen authentication details to access customer systems; affected agencies are required to investigate the full content of impacted correspondence, reset compromised credentials, and secure privileged Azure accounts by April 30, 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.