A black background features a colorful border transitioning from purple to blue. A white, four-square logo is on the top left with the text Evaluating Microsofts Cyber Hack below it, and Upwind in the top right corner.

Evaluating Microsoft’s Cyber Hack

Denise Ashur January 26, 2024

Evaluating Microsoft’s Cyber Hack

Russian state-sponsored threat actor Nobelium recently attacked Microsoft and hacked numerous accounts using a password-spray attack. This allowed them to access a test account and gain access to Microsoft corporate email accounts, including senior leaders. After gaining access, they were able to operate within Microsoft’s infrastructure for more than two months before being discovered.

This indicates a total unawareness of how infrastructure and applications are behaving at runtime, highlighting the importance of runtime data in cloud security.

runtime-data-section-header-1024x117

Leveraging runtime data is the key to securing your cloud infrastructure and applications. With runtime insights, you can identify anomalous human and machine activities and suspicious behavior in real time and quickly take steps to block it, rather than finding out days – or in Microsoft’s case – months later.

Learn more about how Upwind provides protections and controls at runtime:

Make 2024 your year of real-time cloud security.

Contents

Further Reading

Upwind-Sentinel

Upwind for Microsoft Sentinel – Available on Marketplace and Security Store

Security teams should not have to switch between tools to understand what is happening across their cloud environments. That’s why we’re excited to announce that the Upwind solution for Microsoft Sentinel is now available through the Microsoft Marketplace and the Microsoft Security Store. The integration brings Upwind security data directly into Microsoft Sentinel, helping security…
You Can't Crowdsource Your Way to a Live Adversary

You Can’t Crowdsource Your Way to a Live Adversary

Bug bounty programs were built on a single assumption: that finding a vulnerability was the hard, scarce, expensive part worth paying for. That assumption held for about a decade, then AI erased it. When anyone can point a model at your code and receive a plausible-looking finding back in seconds, a crowd of finders stops…
arrayref Supply Chain Attack

arrayref Supply Chain Attack: A One-Line Build Dependency Ran a Backdoor During cargo build

Key Takeaways Executive Summary arrayref 0.3.10 is a hijacked release of a widely used Rust utility crate that added one dependency, proc-macro1, whose build script downloaded and executed a remote binary at compile time. The release was live on crates.io for 86 minutes on August 20, 2026, alongside [email protected] and [email protected] published from the same…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS