Get a Pentest and security assessment of your IT network.

Cyber Security

Microsoft: SolarWinds hackers’ goal was the victims’ cloud data

Microsoft says that the SolarWinds supply chain compromise was to pivot to the victims’ cloud assets after deploying the Sunburst/Solorigate backdoor on their local networks. Microsoft also detailed the step by step procedure used by the attackers to gain access to their victims’s cloud assets. The attackers’ ultimate goal was to generate SAML (Security Assertion Markup Language) tokens to forge authentication tokens allowing access to cloud resources. The NSA also shared mitigation measures against unauthorized cloud access which require making it difficult for threat actors to access to on-premise identity services.

Source: https://www.bleepingcomputer.com/news/security/microsoft-solarwinds-hackers-goal-was-the-victims-cloud-data/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security