home.social

#nobelium — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nobelium, aggregated by home.social.

fetched live
  1. Midnight Blizzard conducts large-scale spear-phishing campaign using RDP files | Microsoft Security Blog

    Link
    📌 Summary:
    Microsoft安全團隊於2024年1月12日偵測到一起針對其企業系統的國家級攻擊,並迅速啟動了應對程序以調查、幹擾惡意活動、減輕襲擊,並阻止攻擊者進一步訪問。經過調查後,該威脅行為者被識別為「午夜暴風雪」(Midnight Blizzard),這是一個由俄羅斯國家支持的黑客組織,亦稱為NOBELIUM。

    🎯 Key Points:
    - 事件時間: 2024年1月12日,Microsoft偵測到國家級攻擊。
    - 應對措施: 啟動調查和幹擾惡意行為,以防止未來攻擊。
    - 威脅行為者: 識別為「午夜暴風雪」,即NOBELIUM,屬於俄羅斯國家支持的黑客集團。
    - 目標: 攻擊針對Microsoft的企業系統,顯示出國家級攻擊的趨勢。
    - 安全行動: Microsoft持續監控並強化其安全防護,以應對類似事件。

    🔖 Keywords:
    #Microsoft #網絡安全 #午夜暴風雪 #NOBELIUM #國家級攻擊

  2. #Russia's #spies keep hacking into #Microsoft in 'ongoing attack,' company says, accessed #sourcecode
    In January, Microsoft disclosed that #MidnightBlizzard (aka #NOBELIUM, #APT29 or #CozyBear) had breached corporate email servers after conducting a password spray attack. Microsoft says that Midnight Blizzard is using secrets found in the stolen data to gain access to some of the company's systems and source code repositories in recent weeks.
    techcrunch.com/2024/03/08/micr

  3. #Russia's #spies keep hacking into #Microsoft in 'ongoing attack,' company says, accessed #sourcecode
    In January, Microsoft disclosed that #MidnightBlizzard (aka #NOBELIUM, #APT29 or #CozyBear) had breached corporate email servers after conducting a password spray attack. Microsoft says that Midnight Blizzard is using secrets found in the stolen data to gain access to some of the company's systems and source code repositories in recent weeks.
    techcrunch.com/2024/03/08/micr

  4. ICYMI: The #Microsoft #Nobelium breach is a flashpoint for everyone to reconsider their calculus on legacy systems on the internet.

    How are you changing the calculus you use to balance business disruption with security risk management?

    #Glassof0J #infosec #cybersecurity #dfir #threatintelligence

    youtu.be/6QqK_Dq4t2w

  5. ICYMI: The #Microsoft #Nobelium breach is a flashpoint for everyone to reconsider their calculus on legacy systems on the internet.

    How are you changing the calculus you use to balance business disruption with security risk management?

    #Glassof0J #infosec #cybersecurity #dfir #threatintelligence

    youtu.be/6QqK_Dq4t2w

  6. In case you missed it, #Microsoft announced on Friday that they got pwnd by Midnight Blizzard (NOBELIUM), whom "used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents."

    Notably Microsoft says that there were no vulnerabilities leveraged as part of this attack: "The attack was not the result of a vulnerability in Microsoft products or services."

    This is a good reminder for us to clean up all of our test artifacts - AD accounts and objects, mailboxes, etc. This isn't talked about too much as part of routine cybersecurity hygiene, but it should be.

    #cybersecurity #cti #threatintel #nobelium

  7. In case you missed it, #Microsoft announced on Friday that they got pwnd by Midnight Blizzard (NOBELIUM), whom "used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of our senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents."

    Notably Microsoft says that there were no vulnerabilities leveraged as part of this attack: "The attack was not the result of a vulnerability in Microsoft products or services."

    This is a good reminder for us to clean up all of our test artifacts - AD accounts and objects, mailboxes, etc. This isn't talked about too much as part of routine cybersecurity hygiene, but it should be.

    #cybersecurity #cti #threatintel #nobelium

  8. devcodef1.com/news/1109770/mic #Microsoft #Hacking #Cybersecurity #Nobelium
    Microsoft confirmed a breach of its systems by Nobelium (also known as Midnight Blizzard) on some corporate networks, including those belonging to senior leadership and legal teams, starting in late November 2023. The attackers gained access using compromised credentials and were able to access a small percentage of corporate email accounts, some documents, and

  9. The #microsoft #security team detected a nation-state attack on our corporate systems on January 12, 2024, and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. Microsoft has identified the threat actor as Midnight Blizzard, the #russian state-sponsored actor also known as #nobelium. msrc.microsoft.com/blog/2024/0

  10. The #microsoft #security team detected a nation-state attack on our corporate systems on January 12, 2024, and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. Microsoft has identified the threat actor as Midnight Blizzard, the #russian state-sponsored actor also known as #nobelium. msrc.microsoft.com/blog/2024/0

  11. Mandiant has gathered sufficient evidence to assess that the activity tracked as UNC2452, the group name used to track the #SolarWinds compromise in December 2020, is attributable to #Nobelium (APT29). #usa #russia #internet #apt #cyber #espionage #threats #backdoor #informatique

    mandiant.com/resources/unc2452

  12. The elite 🇷🇺 Russian state hackers behind last year's massive #SolarWinds #cyber #espionage campaign hardly eased up this year, managing plenty of infiltrations of 🇺🇸 U.S. and allied government agencies and foreign policy think tanks with consummate craft and stealth. #Microsoft has also been involved in the Solarwinds attack which has seen more than 18,000 companies and government institutions being infected with a #backdoor which would allow hackers free access to their networks. #Nobelium (APT29), continue to infiltrate the government agencies, foreign policy think tanks, organizations,.. #usa #russia #internet #apt #threats #informatique

    apnews.com/article/technology-

  13. SolarWinds hackers have a whole bag of new tricks for mass compromise attacks - Enlarge (credit: Getty Images)

    Almost exactly a year ago, secu... - arstechnica.com/?p=1818191 #solarwinds #nobelium #unc2652 #unc3004 #biz&it