Microsoft filing with the SEC to say Russia SVR hacked the email accounts of its own cyber staff in November, they discovered this week: sec.gov/Archives/edgar/data/78

I need to set up a calendar entry for Friday night, called Microsoft Hacked Announcements.

I agree with @alex here, Microsoft needs to do a much more public disclosure.

Microsoft staff use Microsoft 365 email with Exchange Online. Eg I was gossi@microsoft.com.

I think MS needs to explain to M365 customers how mailboxes were accessed via password spraying.

cybervillains.com/@alex/111784

HP have now filed an 8K with the SEC, listing the same threat actor as Microsoft, saying they also got access to their email.

Not stated - their email is also on Microsoft 365, same as MSFT.

This time in May 2023.

sec.gov/Archives/edgar/data/16

Microsoft have detailed technical write up about it's security incident and how to defend against it.

It's really good, kudos to MS for publishing.

microsoft.com/en-us/security/b

Microsoft made a catalogue of errors in how they configured and secured their Microsoft 365 tenants. It is not a Microsoft product defect issue; the directly sell the governance products and services to stop this kind of thing.

Follow

@GossiTheDog Human factors are the hardest to overcome.

· · Web · 0 · 0 · 1
Sign in to participate in the conversation
Mastodon

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!