Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft issues protection guidance in light of recent nation-state cyberattack on US government

Microsoft issues protection guidance in light of recent nation-state cyberattack on US government

Kareem Anderson Kareem Anderson
December 14, 2020
2 min read

Microsoft is issuing guidance in the wake of a targeted cyberattack most recently aimed at parts of the US government. Microsoft’s issuance is both parts, identifying recent nation-state sanctioned attack techniques as well as giving its customer assurance that as of now, “we have not identified any Microsoft product or cloud service vulnerabilities in these investigations.”

According to a post on a company blog title Important steps for customers to protect themselves from recent nation-state cyberattacks, Microsoft list the following techniques that have been used by nefarious agents to conduct the relatively recent sophisticated cyberattacks.

  • An intrusion through malicious code in the SolarWinds Orion product. This results in the attacker gaining a foothold in the network, which the attacker can use to gain elevated credentials. Microsoft Defender now has detections for these files. Also, see SolarWinds Security Advisory.
  • An intruder using administrative permissions acquired through an on-premises compromise to gain access to an organization’s trusted SAML token- signing certificate. This enables them to forge SAML tokens that impersonate any of the organization’s existing users and accounts, including highly privileged accounts.
  • Anomalous logins using the SAML tokens created by a compromised token-signing certificate, which can be used against any on-premises resources (regardless of identity system or vendor) as well as against any cloud environment (regardless of vendor) because they have been configured to trust the certificate. Because the SAML tokens are signed with their own trusted certificate, the anomalies might be missed by the organization.
  • Using highly privileged accounts acquired through the technique above or other means, attackers may add their own credentials to existing application service principals, enabling them to call APIs with the permission assigned to that application.

While the above are highlights mentioned by Microsoft in this particular post, the company’s full 2020 Digital Defense Report goes further in-depth discussing specific criminal groups, their activity during the COVID-19 pandemic, and a community approach to cybersecurity among other things. Even as Microsoft attempts to become a proprietor of cybersecurity, the company acknowledges that its efforts are, “only a small piece of what’s needed to address the challenge.”

Share This Post:

Tags: Cyberattacks | Cybersecurity | Digital Defense Report | Microsoft | nation-state | SAML
Share this article:
Tags:
Cyberattacks Cybersecurity Digital Defense Report Microsoft nation-state SAML
Previous Article Office 365 admins can now exclude specific files from OneDrive sync Next Article Sea of Thieves is offering some free cosmetics for its 1000-day celebrations

Related Articles

YouTube App Shows Ads That Won’t Close During Fullscreen Videos

March 4, 2026
tiktok

TikTok Confirms DMs Will Not Get End-to-End Encryption

March 4, 2026
GPT 5.3

OpenAI GPT-5.3 Instant released, when will you get it, and benchmarks

March 3, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • YouTube App Shows Ads That Won’t Close During Fullscreen Videos
  • TikTok Confirms DMs Will Not Get End-to-End Encryption
  • OpenAI GPT-5.3 Instant released, when will you get it, and benchmarks
  • MSFT stock price today: Microsoft shares rise, investors watch AI execution
  • Claude is down, but Gemini 3.1 Flash-Lite is rolling out right now

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • YouTube App Shows Ads That Won’t Close During Fullscreen Videos
  • TikTok Confirms DMs Will Not Get End-to-End Encryption
  • OpenAI GPT-5.3 Instant released, when will you get it, and benchmarks
  • MSFT stock price today: Microsoft shares rise, investors watch AI execution
  • Claude is down, but Gemini 3.1 Flash-Lite is rolling out right now

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy