Microsoft disclosed a security breach where Russian state-backed hackers, identified as Midnight Blizzard, exploited a weak password on the corporate network. The attackers utilized a password spray attack, targeting a legacy non-production test tenant account with no two-factor authentication (2FA). This allowed them to access a small percentage of Microsoft corporate email accounts, including those of senior executives, cybersecurity, and legal team members. The breach began in late November 2023, but Microsoft only detected it on January 12, raising concerns about potentially two months of uninterrupted access.
The compromised test account, configured inexplicably with extensive permissions, enabled the hackers to pivot and reach highly sensitive employee accounts. Questions arise about why such privileges were granted and not revoked after the testing phase ended. The incident highlights a lapse in basic security hygiene.
Microsoft clarified that there is no evidence of Midnight Blizzard accessing customer environments, production systems, source code, or AI systems. However, skepticism persists among researchers, with concerns about the susceptibility of Microsoft 365 services to similar attack techniques.
Former Microsoft cybersecurity expert Kevin Beaumont emphasized the need for Microsoft to undergo significant technical and cultural transformations, moving away from traditional practices and embracing radical changes to rebuild trust. The incident underscores the importance of robust security measures, including 2FA, and diligent account management to thwart cyber threats.
General Prince Adekunle & Pa S. B. Oshoffa (1980): Music Meets Faith This 1980 Daily Times photograph captures a meaningful… Read More
Conference of Obas, Itoro Hall, Ijebu-Ode (1941): Tradition Meets Colonial Authority This historic photograph from 1941 captures a remarkable gathering… Read More
Nigeria’s Second Republic Governors (1979): Who Is Still Alive Today? The 1979 elections marked the beginning of Nigeria’s Second Republic,… Read More
Benjamin Adekunle, the Butcher who vowed to Kill all Igbos Benjamin Adekunle was born in Kaduna, Nigeria, on June 26,… Read More
THE FALL OF A BILLIONAIRE FROM IJEBU The story of Alhaji Safiriyu Tiamiyu, the man who started ST Soap from… Read More
Who is Scared of Hon. Ibrahim Kunle Olarewaju? Recent desperate attacks against Hon. Ibrahim Kunle Olarewaju have revealed a deep-seated… Read More
This website uses cookies.