CISA Warns of Compromised Microsoft Accounts
ID: c1223cd3-f371-5dff-bb33-1401330899ab
STIX ID: report--c1223cd3-f371-5dff-bb33-1401330899ab
Feed Name: Security Boulevard
CISA issued Emergency Directive 24-02 after Russian APT29 exfiltrated Microsoft corporate email accounts and authentication details; affected federal agencies are required to investigate impacted emails, reset compromised credentials, and implement mitigations. The report describes the attackers' techniques (password spray and misuse of an elevated-privilege application), confirms exfiltration of mailboxes including Microsoft leadership and security/legal staff, and advises monitoring, MFA, credential screening, and permissions reviews to detect and remediate compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
