Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files | Microsoft Security Blog

Link📌 Summary:
Microsoft安全團隊於2024年1月12日偵測到一起針對其企業系統的國家級攻擊,並迅速啟動了應對程序以調查、幹擾惡意活動、減輕襲擊,並阻止攻擊者進一步訪問。經過調查後,該威脅行為者被識別為「午夜暴風雪」(Midnight Blizzard),這是一個由俄羅斯國家支持的黑客組織,亦稱為NOBELIUM。

🎯 Key Points:
- 事件時間: 2024年1月12日,Microsoft偵測到國家級攻擊。
- 應對措施: 啟動調查和幹擾惡意行為,以防止未來攻擊。
- 威脅行為者: 識別為「午夜暴風雪」,即NOBELIUM,屬於俄羅斯國家支持的黑客集團。
- 目標: 攻擊針對Microsoft的企業系統,顯示出國家級攻擊的趨勢。
- 安全行動: Microsoft持續監控並強化其安全防護,以應對類似事件。

🔖 Keywords:
#Microsoft #網絡安全 #午夜暴風雪 #NOBELIUM #國家級攻擊

Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files | Microsoft Security Blog

Since October 22, 2024, Microsoft Threat Intelligence has observed Russian threat actor Midnight Blizzard sending a series of highly targeted spear-phishing emails to individuals in government, academia, defense, non-governmental organizations, and other sectors. This activity is ongoing, and Microsoft will continue to investigate and provide updates as available. Based on our investigation of previous Midnight […]

Microsoft Security Blog
Russian hackers read the emails you sent us, Microsoft warns more customers - More of Microsoft's clients are being warned that emails they exchanged with the company ... https://www.bitdefender.com/blog/hotforsecurity/russian-hackers-read-your-emails-to-us-microsoft-warns-more-customers/ #securitythreats #databreach #guestblog #microsoft #dataloss #cozybear #nobelium
Russian hackers read your emails to us, Microsoft warns more customers

More of Microsoft's clients are being warned that emails they exchanged with the company were accessed by Russian hackers who broke into its systems and spied on staff inboxes.

Hot for Security
Russia-linked APT Nobelium targets French diplomatic entities

French information security agency ANSSI reported that Russia-linked threat actor Nobelium is behind a series of cyber attacks that targeted French diplomatic entities.

Security Affairs

CISA issues emergency order on Microsoft breach by Russian hackers

Affected bodies must take immediate action, agency says

https://www.computing.co.uk/news/4196664/cisa-issues-emergency-order-microsoft-breach-russian-hackers

#cisa #midnightblizzard #russia #nobelium #microsoft #infosec

CISA issues emergency order on Microsoft breach by Russian hackers

The US Cybersecurity and Infrastructure Security Agency (CISA) published its recently issued emergency directive on Thursday, which confirmed that a Russian state-sponsored hacker group was able to steal emails from federal agencies in connection with the breach of Microsoft executive accounts.

📄 Nobelium
by Craig Hart @craigaryhart
A static blog build on top of Notion and Nextjs, deployed on Vercel.
#blog #notion #utterances #notionblog #nextjsblog #vercel #nobelium

https://nobelium.js.org/

Nobelium

Mail-Hack mit Folgen: Russische Hacker klauen Quellcode von Microsoft

Microsoft hat erneut Probleme mit staatlich unterstützten Hackern aus Russland, die sich offenbar Zugriff auf Quellcode und interne Systeme verschaffen konnten. Die Angreifer nutzen dabei offenbar Informatio­nen, die sie bei dem E-Mail-Hack Anfang 2024 erlangt hatten.

WinFuture.de
#Russia's #spies keep hacking into #Microsoft in 'ongoing attack,' company says, accessed #sourcecode
In January, Microsoft disclosed that #MidnightBlizzard (aka #NOBELIUM, #APT29 or #CozyBear) had breached corporate email servers after conducting a password spray attack. Microsoft says that Midnight Blizzard is using secrets found in the stolen data to gain access to some of the company's systems and source code repositories in recent weeks.
https://techcrunch.com/2024/03/08/microsoft-ongoing-cyberattack-russia-apt-29/
Russian spies keep hacking into Microsoft in 'ongoing attack,' company says | TechCrunch

Microsoft says the ongoing hacking is part of the Russian government's efforts to figure out what information Microsoft has on its hackers.

TechCrunch
Update on Microsoft Actions Following Attack by Midnight Blizzard (NOBELIUM)

MSRC Blog: This blog provides an update on the nation-state attack that was detected by the Microsoft Security Team on January 12, 2024. As we shared, on January 19, the security team detected this attack on our corporate email systems and immediately activated our response process. The...

Windows 11 Forum
Російські хакери викрали вихідний код у Microsoft – атака досі триває

На початку цього року Microsoft виявила, що російські державні хакери шпигували за обл

ITC.ua
Midnight Blizzard: Guidance for responders on nation-state attack | Microsoft Security Blog

Microsoft detected a nation-state attack on our corporate systems and immediately activated response process to disrupt and mitigate.

Microsoft Security Blog