/plushcap/analysis/veza/identity-security-lessons-from-midnight-blizzards-breach-of-microsoft

Lessons from the breach: Microsoft and Midnight Blizzard

What's this blog post about?

On January 12, 2024, state-sponsored hacking group Midnight Blizzard breached Microsoft's infrastructure, exploiting excessive permissions granted to a legacy OAuth application and revealing machine identities as the key vulnerability. Limited visibility into true permissions of identities and limitations of role/group-based management contributed to the attack remaining undetected for so long. Veza offers comprehensive visibility into access rights for all identities, detailed insights into specific permissions held by each identity, and risk prioritization based on granular permissions evaluation, helping organizations protect against similar threats.

Company
Veza

Date published
Feb. 21, 2024

Author(s)
Veza

Word count
341

Language
English

Hacker News points
None found.


By Matt Makai. 2021-2024.