Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
Menu
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
  1. Home
  2. News
  3. Microsoft issues protection guidance in light of recent nation-state cyberattack on US government

Microsoft issues protection guidance in light of recent nation-state cyberattack on US government

Kareem Anderson Kareem Anderson
December 14, 2020
2 min read

Microsoft is issuing guidance in the wake of a targeted cyberattack most recently aimed at parts of the US government. Microsoft’s issuance is both parts, identifying recent nation-state sanctioned attack techniques as well as giving its customer assurance that as of now, “we have not identified any Microsoft product or cloud service vulnerabilities in these investigations.”

According to a post on a company blog title Important steps for customers to protect themselves from recent nation-state cyberattacks, Microsoft list the following techniques that have been used by nefarious agents to conduct the relatively recent sophisticated cyberattacks.

  • An intrusion through malicious code in the SolarWinds Orion product. This results in the attacker gaining a foothold in the network, which the attacker can use to gain elevated credentials. Microsoft Defender now has detections for these files. Also, see SolarWinds Security Advisory.
  • An intruder using administrative permissions acquired through an on-premises compromise to gain access to an organization’s trusted SAML token- signing certificate. This enables them to forge SAML tokens that impersonate any of the organization’s existing users and accounts, including highly privileged accounts.
  • Anomalous logins using the SAML tokens created by a compromised token-signing certificate, which can be used against any on-premises resources (regardless of identity system or vendor) as well as against any cloud environment (regardless of vendor) because they have been configured to trust the certificate. Because the SAML tokens are signed with their own trusted certificate, the anomalies might be missed by the organization.
  • Using highly privileged accounts acquired through the technique above or other means, attackers may add their own credentials to existing application service principals, enabling them to call APIs with the permission assigned to that application.

While the above are highlights mentioned by Microsoft in this particular post, the company’s full 2020 Digital Defense Report goes further in-depth discussing specific criminal groups, their activity during the COVID-19 pandemic, and a community approach to cybersecurity among other things. Even as Microsoft attempts to become a proprietor of cybersecurity, the company acknowledges that its efforts are, “only a small piece of what’s needed to address the challenge.”

Share This Post:

Tags: Cyberattacks | Cybersecurity | Digital Defense Report | Microsoft | nation-state | SAML
Share this article:
Tags:
Cyberattacks Cybersecurity Digital Defense Report Microsoft nation-state SAML
Previous Article Office 365 admins can now exclude specific files from OneDrive sync Next Article Sea of Thieves is offering some free cosmetics for its 1000-day celebrations

Related Articles

Chrome tests Google Drive file uploads in the AI Mode compose box

April 14, 2026
Gemini image creation using right click desktop Chrome

Chrome lets you remake images with Gemini on desktop using just a right-click

April 13, 2026
Samsung Display crosses 5 million QD-OLED monitor shipments as demand grows fast, with new panels and strong premium market expansion worldwide.

Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years

April 9, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy