Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts

I have so many questions from this sentence alone. What did they password spray? Microsoft's internal identity provider? Was the non-prod system internet facing? Why isn't MFA enforced?



They got Kerberoasted and don't want to admit it publicly.


Indeed. How can they not be mandating MFA?


Maybe this is why it only affected leadership team. Maybe they can circumvent requirements meant for lowly employees.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: