
Russian State-Sponsored Hackers Breach Microsoft Network and Access Senior Leadership Emails
Russian-state hackers breached Microsoft's corporate network by exploiting a weak password through a password-spraying attack, gaining access to emails and documents belonging to senior executives and employees in security and legal teams. The breach went undetected for about two months, raising concerns about the lack of two-factor authentication and weak password practices. While Microsoft claims no evidence of access to customer environments, some researchers doubt this and call for more transparency and radical transformation in Microsoft's approach to cybersecurity.