Microsoft informs customers that Russian hackers spied on emails
reuters.com
reuters.com
After a while you will stop caring too... it happens to everyone eventually. =3
Employee: Microsoft gives us a 50% "discount" vs the competition but they may get hacked easier.. incentive brain mode: if i save 50%, I may get a raise. If MS gets hacked, then "everyone suffers, so it's not like I'll get the blame for this decision"... Azure 100%!!!
I'm not terribly sure if it's really more MS lack of security posture vs. being a big target as they hold a lot of juicy government targets, etc.. so my comment isn't really to beat up on MS because who knows the key flaw that got them inside yet?
It's definitely their lack of security posture. Their being a big target also doesn't help, but their shithouse attitude and practises is probably their main problem.
Just blaming public enemy of the day. Knowing who actually did it I difficult and not really important either.
It's also not always Russia, there were two cyber attack headlines yesterday and neither appeared to be state actors.
E.g. https://blog.sekoia.io/noname05716-ddosia-project-2024-updat...
"The decision not to mandate VPN usage in Russia, especially given their statement “it is extremely unlikely that there will be any problems”, suggests a possible collaboration between the NoName057(16) group and the Russian state."
I imagine you've also heard of attributions like "Cyrillic layout" (used all over eurasia) or "IP pool associated with a Russian AS" (as if VPS renting isn't a thing or commodity routers in Russia aren't hackable and can't be forced into a botnet)
First it was "a very small percentage of Microsoft corporate email accounts" (their C-suite executives and security teams) and "To date, there is no evidence that the threat actor had any access to customer environments, production systems, source code, or AI systems."
Then it was "access to some of the company's source code repositories and internal systems. To date we have found no evidence that Microsoft-hosted customer-facing systems have been compromised."
And now this.
This wasn’t necessarily a technical vulnerability.
Are you suggesting they'll suddenly have a fit of competence?
That would be super surprising for everyone. Including themselves.
My interpretation is that they are notifying customers who corresponded with compromised Microsoft accounts, not that they are saying customer-use email systems were compromised. Do you read that differently?