Get the latest tech news

CISA Emergency Directive: Nation-State Compromise of Microsoft Corporate Email


This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s Emergency Directive 24-02: Mitigating the Significant Risk

This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s Emergency Directive 24-02: Mitigating the Significant Risk from Nation-State Compromise of Microsoft Corporate Email System. This Emergency Directive requires agencies to analyze the content of exfiltrated emails, reset compromised credentials, and take additional steps to ensure authentication tools for privileged Microsoft Azure accounts are secure. CISA has assessed that the below required actions are most appropriate to understand and mitigate the risk posed by Midnight Blizzard’s possession of the exfiltrated correspondence between FCEB agencies and Microsoft.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Microsoft

Microsoft

Photo of corporate email

corporate email

Photo of state compromise

state compromise

Related news:

News photo

US Warns Agencies of Possible Breach Via Microsoft Hack

News photo

US says Russian hackers stole federal government emails during Microsoft cyberattack

News photo

Microsoft Begins Showing Full Screen Windows 11 Ad on Windows 10 PCs as End of Support Date Looms