Midnight Blizzard and Cloudflare-Atlassian Cybersecurity Incidents: What to Know
ID: bb782e2d-d397-5a30-b584-ade2397ce896
STIX ID: report--bb782e2d-d397-5a30-b584-ade2397ce896
Feed Name: The Hacker News
This article details two nation-state SaaS breaches — Microsoft’s Midnight Blizzard (APT29) and the Cloudflare-Atlassian incident — where attackers exploited password spraying, compromised OAuth tokens, and stale credentials to escalate privileges, maintain persistence via malicious OAuth apps, and exfiltrate sensitive data (senior staff emails and multiple source code repositories); it stresses the importance of continuous SaaS monitoring, strict identity/OAuth controls, and SaaS Security Posture Management.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
