CISA has issued an emergency directive in response to Midnight Blizzard, or Cozy Bear, a Russian threat actor targeting Microsoft email accounts. The group is extracting information to access Microsoft customer systems. Strict security measures, including strong passwords and multi-factor authentication, are strongly recommended by CISA for all organizations (Microsoft included).

  • @[email protected]
    link
    fedilink
    English
    106 months ago

    For your last two questions, the counterpoint is, if even Microsoft can’t stop a dedicated nation state, how can any other major service provider say they haven’t been compromised?

    The standard now is, assume breach. While unfortunate, the industry average for MTTD is in months. Microsoft was at least good enough to detect it within six.

    Can Broadcom or Palo Alto say the same? Amazon, Google, Apple, Cisco?

    • The Stoned Hacker
      link
      English
      56 months ago

      It’s why I think it’s a shame the zero-trust is kinda a buzzword. this is exactly the type of situation where an actual zero trust architecture would be extremely useful.

      • Onno (VK6FLAB)
        link
        fedilink
        English
        26 months ago

        I think that zero trust is not enough.

        I think that you need to assume that you are going to be compromised and put processes and procedures in place before that happens to ensure business continuity.

        • The Stoned Hacker
          link
          English
          66 months ago

          im approaching zero trust as assume everything is compromised until you verify it is not

      • KidOPM
        link
        fedilink
        English
        16 months ago

        Maybe cyber resilience? Quick identify, respond and recover from an incident.