logo

Midnight Blizzard and Cloudflare-Atlassian Cybersecurity Incidents: What to Know

ID: bb782e2d-d397-5a30-b584-ade2397ce896

STIX ID: report--bb782e2d-d397-5a30-b584-ade2397ce896

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

This article details two nation-state SaaS breaches — Microsoft’s Midnight Blizzard (APT29) and the Cloudflare-Atlassian incident — where attackers exploited password spraying, compromised OAuth tokens, and stale credentials to escalate privileges, maintain persistence via malicious OAuth apps, and exfiltrate sensitive data (senior staff emails and multiple source code repositories); it stresses the importance of continuous SaaS monitoring, strict identity/OAuth controls, and SaaS Security Posture Management.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.