A suspected Russian intrusion into Microsoft's corporate systems, which was disclosed in January, also affected US federal government systems, according to the US Cybersecurity and Infrastructure Security Agency.
Attackers claimed to be backed by Russia were inside Microsoft's corporate systems for nearly two months before the company detected their presence, it says in a blog post published on Friday.
The group of attackers revealed to have compromised SolarWinds Orion monitoring software back in December 2020 are claimed to be back again, and Microsoft has given them a new name to boot.
Microsoft claims to have detected what it characterises as nation-state activity by an adversary it calls Nobelium — the SolarWinds attackers who are also known as APT29 and Cozy Bear — trying to gain access to customers of multiple cloud providers, including itself.
GUEST OPINION by Joe Slowik, Gigamon: Network security operations generally and network security monitoring (NSM) evolve more specifically with technology like any other information technology (IT) field.