News: 1706094145

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

What Microsoft's latest email breach says about this IT security heavyweight

(2024/01/24)


Comment For most organizations – especially security vendors – disclosing a corporate email breach, in which executives' internal messages and attachments were stolen, would noticeably ding their stock prices.

But Microsoft apparently doesn't operate by the laws of Wall Street.

Late Friday afternoon, Redmond revealed that Russia's Cozy Bear had, once again, [1]broken into its network and stolen emails and files belonging to the tech titan's leadership team, and cybersecurity and legal employees. According to Microsoft, the intrusion happened in late November 2023, and it only detected it on January 12.

[2]

"The company has not yet determined whether the incident is reasonably likely to materially impact the Company's financial condition or results of operations," the Windows giant disclosed in a [3]filing to investors via the SEC.

[4]

[5]

If history is any indication, however, it won't.

Microsoft declined to answer The Register 's questions about the digital heist, or its security in general. Instead, a spokesperson emailed us the following statement:

Our security team recently detected an attack on our corporate systems attributed to the Russian state-sponsored actor [6]Midnight Blizzard . We immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. The attack was not the result of a vulnerability in Microsoft products or services. To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems. More information is available in our [7]blog .

This marks the second time since 2020 the same gang of Kremlin-backed cyber spies – whom Microsoft now calls Midnight Blizzard, used to track as Nobelium, and most call Cozy Bear – has invaded Microsoft. The first was via the [8]SolarWinds supply-chain attack . Since then, [9]Lapsus$ hoodlums and [10]China's snoops have also busted through Redmond's digital perimeter and stolen source code, a private cryptographic key, government messages, and other important, supposedly secret stuff.

Following the theft of the [11]Microsoft security key that China used to break into US government email accounts in July – and at the [12]urging of US Senator Ron Wyden (D-OR) – the US Cyber Safety Review Board launched an [13]investigation into the Microsoft breach and the larger issues surrounding cloud security.

[14]

That probe, or even an expected publication date, has yet to be released.

Presumably, the review board had begun its Microsoft analysis when Cozy Bear broke into corporate email accounts last year. Here's how Redmond [15]described the latest intrusion:

Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account's permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.

This access, and earlier breaches, could have been prevented, according to Wyden. One main thing is that the intruders got in through an old testing environment, seemingly with no multi-factor authentication in the way. Redmond also warned there may be some "disruption" to its systems as it shores up the security of its legacy IT estate and brings all that up to the same level of defenses as the rest of its empire.

"It is inexcusable that Microsoft still hasn't required multi-factor authentication, which is cybersecurity 101 and would have prevented this latest attack," Wyden told The Register .

"This is yet another wholly avoidable hack that was caused by Microsoft's negligence," he added. "The US government needs to reevaluate its dependence on Microsoft."

[16]

Once, such a privacy breach might be enough to sink a software maker – or at the very least render its name synonymous with a cyber intrusion. But Microsoft seemingly remains immune.

Instead it keeps winning government and enterprise contracts and, with security business revenue [17]topping $20 billion last year, it remains one of the largest cybersecurity vendors on the planet – if not the largest.

[18]Russians invade Microsoft exec mail while China jabs at VMware vCenter Server

[19]Microsoft: China stole secret key that unlocked US govt email from crash debug dump

[20]Russia's Cozy Bear is back and hitting Microsoft Teams to phish top targets

[21]Stolen Microsoft key may have opened up a lot more than US govt email inboxes

"It's kind of like the mafia," Adam Meyers, head of Counter Adversary Operations at CrowdStrike, lamented. "I mean, what are you gonna do, you're gonna switch to Linux? Get out of here. You've got no choice."

In an interview with The Register , Meyers conceded that Microsoft makes a good operating system. He spends more time than he'd like to admit in PowerPoint and other Microsoft applications. And, he added, Redmond has built "pretty robust" cloud infrastructure and email.

"But the thing they are really bad at is the security side," Meyers argued. "So if you're using them for your operating systems, for your productivity applications, for all of your cloud infrastructure, then don't use them for security also, because you're putting all of your eggs in one basket. And that basket has giant, egg-shaped holes in it." ®

Get our [22]Tech Resources



[1] https://www.theregister.com/2024/01/20/chinese_russia_vmware_microsoft/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbFCQukNA7D89yBABjtq-QAAANg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.sec.gov/ix?doc=/Archives/edgar/data/789019/000119312524011295/d708866d8k.htm

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbFCQukNA7D89yBABjtq-QAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbFCQukNA7D89yBABjtq-QAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.microsoft.com/en-us/security/blog/tag/midnight-blizzard-nobelium/

[7] https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/

[8] https://www.theregister.com/2023/10/31/sec_charges_solarwinds_sunburst_fraud/

[9] https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/

[10] https://www.theregister.com/2023/09/06/microsoft_stolen_key_analysis/

[11] https://www.theregister.com/2023/07/21/microsoft_key_skeleton/

[12] https://www.theregister.com/2023/07/31/infosec_in_brief/

[13] https://www.dhs.gov/news/2023/08/11/department-homeland-securitys-cyber-safety-review-board-conduct-review-cloud

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbFCQukNA7D89yBABjtq-QAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbFCQukNA7D89yBABjtq-QAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[17] https://www.microsoft.com/investor/reports/ar23/index.html#:~:text=All%20up%2C%20more%20than%201,across%20clouds%20and%20endpoint%20platforms.

[18] https://www.theregister.com/2024/01/20/chinese_russia_vmware_microsoft/

[19] https://www.theregister.com/2023/09/06/microsoft_stolen_key_analysis/

[20] https://www.theregister.com/2023/08/03/microsoft_teams_cozy_bear/

[21] https://www.theregister.com/2023/07/21/microsoft_key_skeleton/

[22] https://whitepapers.theregister.com/



"a password spray attack to compromise a legacy non-production test tenant account"

Mike 137

So [a] there was a redundant account left active, and [b] there was no password retry lockout in place. Just about the most basic laxity imaginable. And these guys profess to (obligatorily these days via enforced updates) manage our security?

Why give the scumbags these code names?

Empire of the Pussycat

"...Midnight Blizzard, used to track as Nobelium, and most call Cozy Bear..."

Scumbags-1, scumbags-2, etc. would surely be more appropriate.

Re: Why give the scumbags these code names?

Evil Scot

Scumba~1 shirley.

"Microsoft makes a good operating system"

alain williams

Meyers then talks about applications (eg Powerpoint).

Microsoft seems to approach security just as it does testing of software updates: toss it over the wall and let customers do the QA for them.

This approach is bad enough for updates but criminal for security.

Re: "Microsoft makes a good operating system"

Zippy´s Sausage Factory

Give the recent upgrades to Outlook and Teams, they don't make good applications any more.

Re: "Microsoft makes a good operating system"

Robin

When they roll out new functionality (that nobody asked for) Teams really does have vibes of "lone developer working in their bedroom". Except an actual lone developer would probably take more care over the product.

Re: "Microsoft makes a good operating system"

TonyJ

Tried "New" Teams when it first came out. Had to go back to the "Old" Teams because if anyone started their camera or tried to share their screen it resulted in a black screen or frozen image on the screen.

Ok.. fair enough...it's still not really GA, so rolled back.

Then a shortish time later I was forced onto it.

About the only plus at that point was that the black/frozen screen seemed to have been fixed.

But synchronising statuses is right out of the window. I have it showing me/others out of office when the status is actually available. But of course, others will see available. Or maybe not. It's random.

Teams is an abomination. Updated outside of Office with little to no controls. Trying to do far too many things. Skype for Business did communications and tended to do it well. All they needed to do was add some form of persistent chat and it would be absolutely fine. But oh no...let's fuck around with OneDrive and SharePoint integrations and make a dogs dinner out of it.

Re: "Microsoft makes a good operating system"

Mike 137

" This approach is bad enough for updates but criminal for security "

The reality is that updates and security are inseparable unless we just don't give a damn. But, fundamentally, so is code quality to start with. If security were taken seriously at dev time, we wouldn't need so many darned 'updates'.

"The attack was not the result of a vulnerability in Microsoft products or services"

Pascal Monett

Hmm, that is subject to discussion. You let a test ID get password spammed. That's a service, is it not ?

Because if there was no human who mistakenly clicked a link, then it's your products or procedures that are at fault.

And we all remember Borkzilla's zeal at renewing its own domain names, right ?

I hope there will be a bit more fallout on this, but hey, Windows is unavoidable, so . . .

Wonderful............................

Anonymous Coward

..............test systems exposed to the internet...............

..............or maybe ALL systems exposed to the internet...........

I think we should be told!

Re: Wonderful............................

Stuart Castle

They mention that an account was used to access a test tenant. This suggests the system was hosted on the cloud. This makes it difficult to totally isolate the system from the Internet, but they should have put things like IP restrictions, and account lockouts on the system. At least MFA..

'It's kind of like the mafia'

Blazde

Nice head orfice. Shame if somebody broke all your windows. We can help you with that..

do they?

captain veg

"Meyers conceded that Microsoft makes a good operating system."

Has anyone ever seen it? Perhaps they ought to make it available to the public.

-A.

The technology is fundementally flawed

Anonymous Coward

“ What Microsoft's latest email breach says about this IT security heavyweight ”

Programming Department:
Mistakes made while you wait.