Russian state-backed hackers breached Microsoft’s core software systems, company says

(005875.811-:E-000062.43:N-AC:R-SU:C-30:V)   

A Russian state-backed group that Microsoft said hacked into its corporate email accounts was able to gain access to its core software systems, the company announced on Friday.

Microsoft said its security team detected the attack in January and identified the group responsible as Midnight Blizzard, "the Russian state-sponsored actor also known as Nobelium."

"In recent weeks, we have seen evidence that Midnight Blizzard is using information initially exfiltrated from our corporate email systems to gain, or attempt to gain, unauthorized access," Microsoft said in a blog post update on Friday. "This has included access to some of the company’s source code repositories and internal systems."

The company said it has found no evidence that Microsoft-hosted customer-facing systems have been compromised due to the breach.

As of Friday, the incident has "not had a material impact" on Microsoft’s operations, the company stated in an SEC filing.

"The Company has not yet determined that the incident is reasonably likely to materially impact the Company’s financial condition or results of operations," the filing stated.

Midnight Blizzard is apparently attempting to use "secrets" that it has found in the hack, according to Microsoft.

"Some of these secrets were shared between customers and Microsoft in email, and as we discover them in our exfiltrated email, we have been and are reaching out to these customers to assist them in taking mitigating measures," Microsoft said.

The volume of some aspects of the ongoing attack has intensified, increasing as much as 10-fold in February compared to January, Microsoft said. That includes "password sprays," in which a user uses a single common password against multiple accounts on the same application, the company said.

"Across Microsoft, we have increased our security investments, cross-enterprise coordination and mobilization, and have enhanced our ability to defend ourselves and secure and harden our environment against this advanced persistent threat," Microsoft said Friday. "We have and will continue to put in place additional enhanced security controls, detections, and monitoring."

The attack began in November, Microsoft said. The company was able to remove the hacker’s access to the email accounts on Jan. 13, according to a company filing with the SEC.

The company said in its SEC filing on Friday that it continues to coordinate with federal law enforcement on the ongoing investigation into the incident.

Source: https://abcnews.go.com/International/microsoft-russian-state-backed-hack-update/story?id=107927553



Jan‘s Advertisement
2005: Zimbabwe: Mugabe rampage leaves 1.5 million Blacks homeless 30,000 arrested
Just as Eddie Cross of the MDC predicted a short while back, Mugabe has wiped out homes, and even bulldozed grocery stores in mid-winter. Eddie Cross estimated 2 million Blacks would be homeless.


Jan‘s Advertisement
6 Pics: When South Africa was White and VIBRANT! - The Hanging building!
This building still exists in Johannesburg. It was already built and looking great in the mid-1980s when I came to work in Johannesburg. Someone back then told me that the floors of this building are hanging. I did not quite know what to think of it, but its design is strange and when you look at the bottom, youll see the whole building is held up by a central column. (Just like those buildings of 911).


Jan‘s Advertisement
Video & Audio: Enormous Lies about the Confederates & the Evil Malice of the Freeing of the Slaves
In this show we discuss the Confederates and the American Civil War which took America in the wrong direction and which negatively impacts America to this day.