HomeSecurityCrowdStrike releases new Azure security tool after failed hack

CrowdStrike releases new Azure security tool after failed hack

Leading cybersecurity firm CrowdStrike was notified by Microsoft that hackers had attempted to read the company's emails through a breach of Microsoft Azure credentials.

Earlier this month, it was discovered that network management company SolarWinds suffered a cyberattack, where threat actors modified their software to install backdoors into customer networks via a supply chain attack.

Due to this attack, SolarWinds customers are trying to analyze their networks to see if they were victims of the breach.

After conducting an analysis of its internal and production environments, CrowdStrike said Thursday that it found no signs that the SolarWinds breach impacted it.

CrowdStrike Azure

Attackers breached Microsoft reseller accounts

While conducting their investigation, CrowdStrike was notified by Microsoft on December 15 that a compromised Microsoft Azure reseller account was used to read CrowdStrike emails.

A source told Reuters that the compromised reseller account had attempted to grant Office 365 “Read” privileges to access CrowdStrike’s emails. Since CrowdStrike does not use Office 365, the attack failed.

Microsoft senior manager Jeff Jones told Reuters that this attack was carried out by attackers stealing credentials for Microsoft's reseller account, not vulnerabilities in its cloud products or services

“Our investigation into recent attacks has identified incidents involving misuse of credentials to gain access, which can take a variety of forms,” Jones told Reuters. “We have not identified any vulnerabilities or breaches of Microsoft products or cloud services.”

In two articles published this month, Microsoft revealed how stolen credentials and access tokens are being used to target Azure customers. administrators to read these articles to learn more about these attacks.

After learning of this attempted attack, CrowdStrike analyzed the Azure environment and determined that it had not been compromised. However, during this analysis, they found it difficult to use Azure management tools to enumerate the privileges granted to third-party resellers and partners.

To help administrators analyze their Microsoft Azure environment and see what permissions have been granted to third-party resellers and partners, CrowdStrike has released the free CrowdStrike Reporting Tool for Azure (CRT).

CrowdStrike releases new Azure security tool after failed hack

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS