Russia Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/russia/ Breaking news about the market for products, systems and services for the U.S. intelligence community Fri, 10 Apr 2026 13:43:22 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg Russia Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/russia/ 32 32 59882712 NSA, FBI warn of Russian GRU threats against routers https://intelligencecommunitynews.com/nsa-fbi-warn-of-russian-gru-threats-against-routers/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-russian-gru-threats-against-routers Fri, 10 Apr 2026 13:43:22 +0000 https://intelligencecommunitynews.com/?p=44296 On April 7, the National Security Agency (NSA) and other agencies co-sealed a Federal Bureau of Investigation (FBI) public service...

The post NSA, FBI warn of Russian GRU threats against routers appeared first on Intelligence Community News.

]]>
On April 7, the National Security Agency (NSA) and other agencies co-sealed a Federal Bureau of Investigation (FBI) public service announcement, “Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information” to encourage further defensive actions.

The U.S. Department of Justice, FBI, and international law enforcement partners recently disrupted a GRU network of compromised small-office home-office (SOHO) routers used as part of malicious hijacking operations. All device owners and network defenders are encouraged to take action to remediate and reduce the attack surface of similar edge devices.

Russian GRU 85th Main Special Service Center (85th GTsSS) cyber actors — also known as APT28, Fancy Bear, and Forest Blizzard — have collected credentials and exploited vulnerable routers worldwide, including compromising TP-Link routers using CVE-2023-50224.The GRU has indiscriminately compromised a wide pool of US and global victims, especially targeting information related to military, government, and critical infrastructure.

The FBI, NSA, and co-sealing agencies encourage SOHO router users to change default usernames and passwords, disable remote management interfaces from the Internet, update to latest firmware versions, and upgrade end-of-support devices. Users should also carefully consider certificate warnings in web browsers and email clients.

Organizations that allow telework should review relevant policies regarding how employees access sensitive data — including the use of virtual private networks (VPNs) or hardened application configurations.

If you, or someone you know, suspects that you have been targeted or compromised by a Russian GRU cyber intrusion, NSA recommends reporting the activity to your local FBI field office, filing a complaint with the Internet Crime Complaint Center (IC3), or otherwise following your organization’s incident reporting requirements.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA, FBI warn of Russian GRU threats against routers appeared first on Intelligence Community News.

]]>
44296
NSA, FBI warn of pro-Russia Hacktivist threats https://intelligencecommunitynews.com/nsa-fbi-warn-of-pro-russia-hacktivist-threats/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-pro-russia-hacktivist-threats Mon, 15 Dec 2025 13:17:23 +0000 https://intelligencecommunitynews.com/?p=43400 On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security...

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
On December 9, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA) and over 20 others to release the Cybersecurity Advisory (CSA), “Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure,” and provide recommended mitigations to reduce the likelihood and impact of related incidents.

The authoring agencies have observed pro-Russia hacktivist groups—attributed to the Cyber Army of Russia Reborn (CARR), Z-Pentest, NoName057(16), Sector16, and affiliated groups—capitalizing on the widespread availability of inadequately secured virtual network computing (VNC) connections to infiltrate operational technology (OT) control devices within critical infrastructure systems and conduct cyber operations against organizations worldwide.

The groups’ ongoing opportunistic targeting methodology can lead to broad targeting and indiscriminate compromise of critical infrastructure entities, including those in Water and Wastewater, Food and Agriculture, and the Energy Sector. Further, their observed lack of strategic focus increases the likelihood of targeting of unintended victims, and tends to result in haphazard attacks with unanticipated damages.

These actors are primarily seeking notoriety with their actions, regularly self-attributing and exaggerating cyberattacks on social media and in group channels to garner attention from peers and the media. Despite this, and their lack of sophisticated ability, actors have been observed willfully causing damage to vulnerable critical infrastructure.

These actors utilize simple, cheap, and easy-to-replicate tactics, techniques, and procedures (TTPs) for the ease of dissemination and replication across various entities, increasing the risk of wide-spread adoption by other cyber actors and escalated frequency of attacks. The authoring agencies warn there is risk that continued attacks may result in further harm or consequences.

Critical infrastructure entities, OT asset owners and operators, and OT device manufactures are encouraged to become familiar with the outlined TTPs and apply the recommended mitigation strategies to reduce the likelihood and impact of incidents related to pro-Russia hacktivists. The report also provides incident response actions organizations should take if compromise is detected.

Read the full report here.

Source: NSA

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post NSA, FBI warn of pro-Russia Hacktivist threats appeared first on Intelligence Community News.

]]>
43400
NSA warns of Russian State-sponsored cyber campaign https://intelligencecommunitynews.com/nsa-warns-of-russian-state-sponsored-cyber-campaign/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-warns-of-russian-state-sponsored-cyber-campaign Thu, 22 May 2025 13:13:04 +0000 https://intelligencecommunitynews.com/?p=41774 On May 21, the National Security Agency (NSA) announced that it is joining several United States and foreign entities to release...

The post NSA warns of Russian State-sponsored cyber campaign appeared first on Intelligence Community News.

]]>
On May 21, the National Security Agency (NSA) announced that it is joining several United States and foreign entities to release the Cybersecurity Advisory (CSA), “Russian GRU Targeting Western Logistics Entities and Technology Companies,” to call attention to a Russia state-sponsored cyber campaign targeting Western government organizations and commercial logistics entities, transportation services, and technology companies, including those involved in providing assistance to Ukraine.

The Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (Unit 26165) has been conducting this cyber-espionage campaign—using both previously disclosed and novel tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs)—since at least February 2022. This cyber actor is commonly known in the cybersecurity community as APT28, Fancy Bear, Forest Blizzard, or BlueDelta.

In addition to targeting entities involved in supplying aid to Ukraine, Unit 26165 actors can be linked to the targeting of Internet-connected cameras in Ukraine and bordering countries, likely to monitor the movement of shipments into Ukraine.

The CSA provides guidance for at-risk organizations to posture their defenses against potential targeting by Unit 26165 through recommendations for increased monitoring and threat hunting for known TTPs and IOCs.

The report outlines several of the TTPs Unit 26165 actors use to gain access to targeted entities, including password spraying, spearphishing, and modification of Microsoft Exchange mailbox permissions. Additionally, the advisory highlights the specific risk to a range of small office/home office (SOHO) devices, as Unit 26165 actors abuse vulnerabilities associated with a range of brands and models to conduct covert cyber operations and proxy malicious activity.

The authoring agencies expect this cyber-espionage campaign to continue. To defend against and mitigate these threats, at-risk entities should anticipate targeting by Unit 26165 actors, become familiar with the known TTPs and IOCs associated with Unit 26165, and implement the mitigations listed in the CSA.

Read the full report here.

Source: NSA

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

 

The post NSA warns of Russian State-sponsored cyber campaign appeared first on Intelligence Community News.

]]>
41774
Russia steps up election undermining efforts, IC says https://intelligencecommunitynews.com/russia-steps-up-election-undermining-efforts-ic-says/?utm_source=rss&utm_medium=rss&utm_campaign=russia-steps-up-election-undermining-efforts-ic-says Tue, 05 Nov 2024 15:34:17 +0000 https://intelligencecommunitynews.com/?p=40168 On November 4, the Office of the Director of National Intelligence (ODNI), the Federal Bureau of Investigation (FBI), and the...

The post Russia steps up election undermining efforts, IC says appeared first on Intelligence Community News.

]]>
On November 4, the Office of the Director of National Intelligence (ODNI), the Federal Bureau of Investigation (FBI), and the Cybersecurity and Infrastructure Security Agency (CISA) released the following statement:

“Since our statement on Friday, the IC has been observing foreign adversaries, particularly Russia, conducting additional influence operations intended to undermine public confidence in the integrity of U.S. elections and stoke divisions among Americans. The IC expects these activities will intensify through election day and in the coming weeks, and that foreign influence narratives will focus on swing states.

Russia is the most active threat. Influence actors linked to Russia in particular are manufacturing videos and creating fake articles to undermine the legitimacy of the election, instill fear in voters regarding the election process, and suggest Americans are using violence against each other due to political preferences, judging from information available to the IC. These efforts risk inciting violence, including against election officials. We anticipate Russian actors will release additional manufactured content with these themes through election day and in the days and weeks after polls close.

  • The IC assesses that Russian influence actors recently posted and amplified an article falsely claiming that U.S. officials across swing states plan to orchestrate election fraud using a range of tactics, such as ballot stuffing and cyber attacks.
  • Russian influence actors also manufactured and amplified a recent video that falsely depicted an interview with an individual claiming election fraud in Arizona, which involved creating fake overseas ballots and changing voter rolls to favor Vice President Kamala Harris. The Arizona Secretary of State has already refuted the video’s claim as false.

Iran also remains a significant foreign influence threat to U.S. elections. As noted in a prior update, we have assessed that Iran has conducted malicious cyber activities to compromise former President Trump’s campaign. Iranian influence actors may also seek to create fake media content intended to suppress voting or stoke violence, as they have done in past election cycles. We previously reported that Iran also remains determined to seek revenge against select former US officials whom it views as culpable for the death of Islamic Revolutionary Guard Corps-Qods Force (IRGC-QF) Commander Soleimani in January 2020. It has repeatedly highlighted former President Donald Trump among its priority targets for retribution.

In light of continued influence efforts by foreign adversaries and the increasing volume of inauthentic content online, CISA recommends voters seek out information from trusted, official sources, in particular, state and local election officials.

The FBI and CISA encourage campaigns and election infrastructure stakeholders to report information concerning suspicious or criminal activity to their local Election Crime Coordinators via FBI field office (www.fbi.gov/fieldoffices), by calling 1-800-CALL-FBI (1-800-225-5324), or online at ic3.gov. Cyber incidents impacting election infrastructure can also be reported to CISA by calling 1-844-Say-CISA (1-844-729-2472), emailing report@cisa.dhs.gov, or reporting online at cisa.gov/report. Election infrastructure stakeholders and the public can find additional resources about how to protect against cyber and physical threats at CISA’s #PROTECT2024 (https://www.cisa.gov/protect2024).”

Source: ODNI

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Russia steps up election undermining efforts, IC says appeared first on Intelligence Community News.

]]>
40168
ODNI, FBI, and CISA release statement on Russian election influence efforts https://intelligencecommunitynews.com/odni-fbi-and-cisa-release-statement-on-russian-election-influence-efforts/?utm_source=rss&utm_medium=rss&utm_campaign=odni-fbi-and-cisa-release-statement-on-russian-election-influence-efforts Mon, 04 Nov 2024 12:37:01 +0000 https://intelligencecommunitynews.com/?p=40151 On November 1, the Office of the Director of National Intelligence (ODNI), the Federal Bureau of Investigation (FBI), and the...

The post ODNI, FBI, and CISA release statement on Russian election influence efforts appeared first on Intelligence Community News.

]]>
On November 1, the Office of the Director of National Intelligence (ODNI), the Federal Bureau of Investigation (FBI), and the Cybersecurity and Infrastructure Security Agency (CISA) released the following statement:

“The IC assesses that Russian influence actors manufactured a recent video that falsely depicted individuals claiming to be from Haiti and voting illegally in multiple counties in Georgia. This judgment is based on information available to the IC and prior activities of other Russian influence actors, including videos and other disinformation activities. The Georgia Secretary of State has already refuted the video’s claims as false.

Russian influence actors also manufactured a video falsely accusing an individual associated with the Democratic presidential ticket of taking a bribe from a U.S. entertainer.

This Russian activity is part of Moscow’s broader effort to raise unfounded questions about the integrity of the US election and stoke divisions among Americans, as detailed in prior ODNI election updates. In the lead up to election day and in the weeks and months after, the IC expects Russia to create and release additional media content that seeks to undermine trust in the integrity of the election and divide Americans.”

Source: ODNI

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post ODNI, FBI, and CISA release statement on Russian election influence efforts appeared first on Intelligence Community News.

]]>
40151
ODNI, FBI, and CISA issue statement on Russian election misinformation https://intelligencecommunitynews.com/odni-fbi-and-cisa-issue-statement-on-russian-election-misinformation/?utm_source=rss&utm_medium=rss&utm_campaign=odni-fbi-and-cisa-issue-statement-on-russian-election-misinformation Mon, 28 Oct 2024 13:37:46 +0000 https://intelligencecommunitynews.com/?p=40089 On October 25, the Office of the Director of National Intelligence (ODNI), the Federal Bureau of Investigation (FBI), and the...

The post ODNI, FBI, and CISA issue statement on Russian election misinformation appeared first on Intelligence Community News.

]]>
On October 25, the Office of the Director of National Intelligence (ODNI), the Federal Bureau of Investigation (FBI), and the Cybersecurity and Infrastructure Security Agency (CISA) released the following statement:

“The IC assesses that Russian actors manufactured and amplified a recent video that falsely depicted an individual ripping up ballots in Pennsylvania, judging from information available to the IC and prior activities of other Russian influence actors, including videos and other disinformation activities. Local election officials have already debunked the video’s content.”

“This Russian activity is part of Moscow’s broader effort to raise unfounded questions about the integrity of the US election and stoke divisions among Americans, as detailed in prior ODNI election updates. In the lead up to election day and in the weeks and months after, the IC expects Russia to create and release additional media content that seeks to undermine trust in the integrity of the election and divide Americans.”

Source: ODNI

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post ODNI, FBI, and CISA issue statement on Russian election misinformation appeared first on Intelligence Community News.

]]>
40089
NSA advises on Russian SVR cyber ops https://intelligencecommunitynews.com/nsa-advises-on-russian-svr-cyber-ops/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-advises-on-russian-svr-cyber-ops Fri, 11 Oct 2024 11:47:13 +0000 https://intelligencecommunitynews.com/?p=39973 On October 10, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the United States Cyber Command’s...

The post NSA advises on Russian SVR cyber ops appeared first on Intelligence Community News.

]]>
On October 10, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the United States Cyber Command’s Cyber National Mission Force (CNMF), and the United Kingdom National Cyber Security Centre (NCSC) to warn network defenders about ongoing Russian Federation Foreign Intelligence Service (SVR) cyber threats and to recommend rapid countermeasures for security patching and mitigating systems.

The joint Cybersecurity Advisory (CSA), “Update on SVR Cyber Operations and Vulnerability Exploitation,” highlights how Russian SVR cyber actors are currently exploiting a set of software vulnerabilities and have intentions to exploit additional vulnerabilities. It provides a detailed list of publicly disclosed common vulnerabilities and exposures (CVEs) and a list of mitigations to improve cybersecurity posture based on the SVR cyber actors’ operations.

“This activity is a global threat to the government and private sectors and requires thorough review of security controls, including prioritizing patches and keeping software up to date,” said Dave Luber, NSA’s Cybersecurity Director. “Our updated guidance will help network defenders detect these intrusions and ensure they are taking steps to secure their systems.”

According to the CSA, SVR cyber actors are using a range of tactics, techniques, and procedures (TTPs) including, but not limited to, spearphishing, password spraying, abuse of supply chain and trusted relationships, custom and bespoke malware, cloud exploitation, and living off the land techniques. They gain initial access, escalate privileges, move laterally, maintain persistence in victim networks and cloud environments, and exfiltrate information. They often conceal their activity using Tor, leased and compromised infrastructure, and proxies.

To disrupt this activity, the report’s authors recommend baselining authorized devices and scrutinizing systems accessing their networks that do not adhere to the baseline, among other mitigations.

Since 2021, the SVR actors – also tracked as APT29, Midnight Blizzard (formerly Nobelium), the Dukes, and Cozy Bear – have consistently targeted U.S., European, and global entities in the defense, technology, and finance sectors. Their intent is to collect foreign intelligence and enable future cyber operations, including in support of Russia’s ongoing invasion of Ukraine.

A CSA published in April 2021, “Russian SVR Targets U.S. and Allied Networks,” highlighted the SVR’s exploitation of CVEs for initial access. Since then, SVR cyber actors have exploited vulnerabilities at a mass scale to target victims worldwide across many sectors. A CSA released in February 2024, “SVR Cyber Actors Adapt Tactics for Initial Cloud Access,” highlighted additional information on the exploitation of cloud environments and the use of proxies.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA advises on Russian SVR cyber ops appeared first on Intelligence Community News.

]]>
39973
NSA, FBI, CISA issue warning about Russian military cyber actors https://intelligencecommunitynews.com/nsa-fbi-cisa-issue-warning-about-russian-military-cyber-actors/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-cisa-issue-warning-about-russian-military-cyber-actors Fri, 06 Sep 2024 13:54:50 +0000 https://intelligencecommunitynews.com/?p=39679 On September 5, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security...

The post NSA, FBI, CISA issue warning about Russian military cyber actors appeared first on Intelligence Community News.

]]>
On September 5, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and international allies in publishing the Cybersecurity Advisory (CSA) “Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure” to detail malicious activity used for the purposes of espionage, sabotage, and reputational harm since at least 2020.

The authoring agencies assess cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) are responsible for the malicious activity. The report includes recommended mitigations to improve cybersecurity posture.

“This Cybersecurity Advisory contains comprehensive information about GRU Unit 29155 cyber actors and their cyber activity,” said Dave Luber, NSA’s cybersecurity director. “It is important for organizations to use this information and take immediate action to secure data and mitigate any harm caused by these malicious cyber actors.”

According to the CSA, the GRU Unit 29155 Cyber Component is responsible for deploying the destructive WhisperGate malware against Ukrainian victim organizations as early as January 2022. Additionally, Unit 29155 cyber actors have conducted computer network operations against numerous North Atlantic Treaty Organizations (NATO) in Europe and North American, as well as in Latin America and Central Asia. The activity includes destructive cyber campaigns, infrastructure scanning, and data exfiltration, with a primary focus since early 2022 of disrupting aid to Ukraine.

The CSA’s authors recommend taking the following actions today to mitigate malicious cyber activity:

  • Prioritize routine system updates and remediate known exploited vulnerabilities.
  • Segment networks to prevent the spread of malicious activity.
  • Enable phishing-resistant multifactor authentication (MFA) for all externally facing account services, especially for webmail, VPN, and accounts that access critical systems.

Other U.S. agencies and allies co-sealing the CSA are the U.S. Department of the Treasury, the U.S. Department of State (Rewards for Justice program), the United States Cyber Command Cyber National Mission Force (CNMF), the Netherlands Defence Intelligence and Security Service (MIVD), Czech Military Intelligence (VZ), the Czech Republic Security Information Service (BIS), the German Federal Office for the Protection of the Constitution (BfV), the Estonian Internal Security Service (KAPO), the Latvian State Security Service (VDD), Security Service of Ukraine (SBU), Computer Emergency Response Team of Ukraine (DERT-UA), the Canadian Security Intelligence Service (CSIS), the Communications Security Establishment Canada (CSE), the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), and the United Kingdom National Cyber Security Centre (NCSC-UK).

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA, FBI, CISA issue warning about Russian military cyber actors appeared first on Intelligence Community News.

]]>
39679
NSA, cybersecurity partners issue urgent OT threat warning https://intelligencecommunitynews.com/nsa-cybersecurity-partners-issue-urgent-ot-threat-warning/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-cybersecurity-partners-issue-urgent-ot-threat-warning Thu, 02 May 2024 13:30:47 +0000 https://intelligencecommunitynews.com/?p=38574 Pro-Russia hacktivists are conducting malicious cyber activity against operational technology (OT) devices and critical infrastructure organizations are encouraged to implement...

The post NSA, cybersecurity partners issue urgent OT threat warning appeared first on Intelligence Community News.

]]>
Pro-Russia hacktivists are conducting malicious cyber activity against operational technology (OT) devices and critical infrastructure organizations are encouraged to implement mitigations, according to a Fact Sheet released on May 1 by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Department of Agriculture (USDA), Multi-State Information Sharing and Analysis Center (MS-ISAC), the U.K. National Cyber Security Centre, and the Canadian Centre for Cyber Security.

According to the report, “Defending OT Operations Against Ongoing Pro-Russia Hacktivist Activity,” the hacktivists are compromising small-scale OT systems in North American and European Water and Wastewater Systems (WWS), dams, energy, and food and agriculture sectors.

Since 2022, the authoring organizations observed malicious activity and are releasing this joint guidance to share information and mitigations associated with the pro-Russia hacktivists’ recent cyber operations against OT.

“This year we have observed pro-Russia hacktivists expand their targeting to include vulnerable North American and European industrial control systems,” said Dave Luber, NSA’s director of cybersecurity. “NSA highly recommends critical infrastructure organizations’ OT administrators implement the mitigations outlined in this report, especially changing any default passwords, to improve their cybersecurity posture and reduce their system’s vulnerability to this type of targeting.”

The recommendations in this report include hardening human machine interfaces, limiting exposure of OT systems to the internet, using strong and unique passwords, and implementing multifactor authentication for all access to the OT network.  These recommendations are helpful to counter any actors using these techniques.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA, cybersecurity partners issue urgent OT threat warning appeared first on Intelligence Community News.

]]>
38574
CISA issues emergency directive after Microsoft corporate email system breach https://intelligencecommunitynews.com/cisa-issues-emergency-directive-after-microsoft-corporate-email-system-breach/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-issues-emergency-directive-after-microsoft-corporate-email-system-breach Fri, 12 Apr 2024 11:58:48 +0000 https://intelligencecommunitynews.com/?p=38370 The Russian state-sponsored cyber actor known as Midnight Blizzard has exfiltrated email correspondence between Federal Civilian Executive Branch (FCEB) agencies and Microsoft through...

The post CISA issues emergency directive after Microsoft corporate email system breach appeared first on Intelligence Community News.

]]>
The Russian state-sponsored cyber actor known as Midnight Blizzard has exfiltrated email correspondence between Federal Civilian Executive Branch (FCEB) agencies and Microsoft through a successful compromise of Microsoft corporate email accounts, the Cybersecurity and Infrastructure Security Agency (CISA) announced April 2. Microsoft has disclosed the incident and follow on updates through multiple communications, beginning in January 2024: Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard | MSRC Blog | Microsoft Security Response Center and Update on Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard | MSRC Blog | Microsoft Security Response Center.

The threat actor is using information initially exfiltrated from the corporate email systems, including authentication details shared between Microsoft customers and Microsoft by email, to gain, or attempt to gain, additional access to Microsoft customer systems. According to Microsoft, Midnight Blizzard has increased the volume of some aspects of the intrusion campaign, such as password sprays, by as much as 10-fold in February, compared to an already large volume seen in January 2024.

Midnight Blizzard’s successful compromise of Microsoft corporate email accounts and the exfiltration of correspondence between agencies and Microsoft presents a grave and unacceptable risk to agencies. This Emergency Directive requires agencies to analyze the content of exfiltrated emails, reset compromised credentials, and take additional steps to ensure authentication tools for privileged Microsoft Azure accounts are secure. CISA has assessed that the below required actions are most appropriate to understand and mitigate the risk posed by Midnight Blizzard’s possession of the exfiltrated correspondence between FCEB agencies and Microsoft.

Microsoft and CISA have notified all federal agencies whose email correspondence with Microsoft was identified as exfiltrated by Midnight Blizzard. This Directive will refer to that group of agencies as “affected agencies.”

In addition, Microsoft has represented to CISA that for the subset of affected agencies whose exfiltrated emails contain authentication secrets, such as credentials or passwords, Microsoft will provide metadata for such emails to those agencies.

Finally, Microsoft has agreed to provide metadata for all exfiltrated federal agency correspondence—regardless of the presence of authentication secrets—upon the request of the National Cyber Investigative Joint Task Force (NCIJTF), which has volunteered to be the single federal point of contact for this incident.

Source: CISA

Your competitors read IC News each day. Shouldn’t you? Learn more about our subscription options, and keep up with every move in the IC contracting space.

The post CISA issues emergency directive after Microsoft corporate email system breach appeared first on Intelligence Community News.

]]>
38370