Security
  • Menu
  • All Tips
  • FAQs
  • Categories
  • Guidelines
  • Data Security Support
  • Tools
  • Have I Been Pwned?
  • Pwned Passwords
  • Email Checker
  • Password Generator
  • My IP
  • Privacy
DATA PRIVACY NOTICE AND CONSENT FORM

Cloudstaff is committed to protecting the privacy of its data subjects, and ensuring the safety and security of personal data under its control and custody. This policy provides information on what personal data is gathered by Cloudstaff Security Tips about its current, past, and prospective employees; how it will use and process this; how it will keep this secure; and how it will dispose of it when it is no longer needed. This information is provided in compliance with the Philippine Republic Act No. 10173, also known as, the Data Privacy Act of 2012 (DPA) and its Implementing Rules and Regulations (DPA-IRR). It sets out Cloudstaffs’ data protection practices designed to safeguard the personal data of individuals it deals with, and also to inform such individuals of their rights under the Act.

The personal data obtained from this application is entered and stored within the Cloudstaff system and will only be accessed by the Cloudstaff’s authorized personnel. Cloudstaff have instituted appropriate organizational, technical and cloud security measures (Amazon Web Services Shared Responsibility) to ensure the protection of the users personal data.

Information collected will be automatically deleted after three (3) years inactivity.

Furthermore, the information collected and stored in the application are as follows:
  • Given Name
  • Family Name
  • Avatar [Profile Picture]

USER CONSENT

I have read the Data Privacy Statement and expressed my consent for Cloudstaff to collect, record, organize, update or modify, retrieve, consult, use, consolidate, block, erase or destruct my personal data as part of my information.

I hereby affirm my right to be informed, object to processing, access and rectify, suspend or withdraw my personal data, and be indemnified in case of damages pursuant to the provisions of the Republic Act No. 10173 of the Philippines, Data Privacy Act of 2012 and its corresponding Implementing Rules and Regulations.

If you want to exercise any of your rights, or if you have any questions about how we process your personal data, please contact Cloudstaff’s Data Protection Officer, through the following channel:

Email to privacy@cloudstaff.com

  • Log in Now
High-Level Microsoft Executives' Email Security Compromised in Advanced Cyber Attack Attributed to Russian APT Group

On Friday, Microsoft publicly disclosed that it had fallen victim to a sophisticated nation-state attack targeting its corporate systems. This breach resulted in the unauthorized access and theft of emails and attachments belonging to senior executives, as well as individuals within the company's cybersecurity and legal departments. The orchestrator of this attack was identified as the Russian advanced persistent threat group Midnight Blizzard, formerly known as Nobelium or APT29. Notably, this group has also been associated with monikers such as BlueBravo, Cloaked Ursa, Cozy Bear, and The Dukes.

Microsoft revealed that the cyber campaign initiated by Midnight Blizzard began in late November 2023 and was discovered by the company on January 12, 2024. Upon detection, Microsoft promptly launched an investigation and took immediate steps to disrupt and mitigate the malicious activity. The attack vector involved a password spray attack targeting a legacy non-production test tenant account. Once compromised, the attackers utilized the account's permissions to gain access to a limited number of Microsoft corporate email accounts, specifically targeting members of the senior leadership team and employees in cybersecurity, legal, and other functions. The threat actors successfully exfiltrated some emails and attached documents during this breach.

Crucially, Microsoft emphasized that the security incident was not a result of any vulnerabilities in its products. Furthermore, there is no evidence to suggest that the attackers gained access to customer environments, production systems, source code, or artificial intelligence systems.

Despite the disclosure, Microsoft did not provide specific details regarding the number of email accounts infiltrated or the nature of the information accessed. The company, however, assured ongoing efforts to notify employees affected by the incident.

This incident is not the first time Midnight Blizzard has targeted Microsoft. In December 2020, the group was responsible for a high-profile breach aimed at siphoning source code related to Azure, Intune, and Exchange components. Additionally, in June 2021, Midnight Blizzard breached three of Microsoft's customers using password spraying and brute-force attacks.

The Microsoft Security Response Center (MSRC) underscored that this latest attack highlights the persistent risk posed to organizations by well-resourced nation-state threat actors like Midnight Blizzard. The group, previously implicated in the SolarWinds supply chain compromise, continues to be a notable force in the realm of advanced cyber threats.


Source: https://thehackernews.com/2024/01/microsofts-top-execs-emails-breached-in.html


Caitlin Joyce (CaitlinG) Galanza | News
Created: January 23 2024 | Updated: on 1/23/24
Comments


  2021 © Mazer

Security Tips v2.0.1 | Crafted with by Saugi