CyberWire Daily

Blizzard warning: Amazon freezes midnight hack.

Sep 2, 2025
Michael Sikorski, CTO of Unit 42 at Palo Alto Networks, joins forces with Thomas P. Bossert, former Homeland Security Advisor, to delve into the complexities of cyber defense. They discuss a recent disruption of Russia’s Midnight Blizzard cyber campaign and the implications for national security. The conversation highlights the urgency of transitioning from reactive to proactive cybersecurity measures, emphasizing strategies that organizations must adopt to safeguard sensitive data. Tune in for insights on navigating the dynamic realm of cyber threats.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

APT29 Shift To Stealthy Credential Theft

  • Amazon disrupted APT29's watering-hole campaign that redirected visitors to fake Cloudflare pages and stole device auth tokens.
  • The operation shows APT29 shifted from MFA bypass to stealthier credential theft using obfuscated JavaScript and randomization.
ADVICE

Enforce And Monitor Device Authorizations

  • Enforce multi-factor authentication and monitor device authorizations to limit attackers using stolen tokens.
  • Review login activity and revoke unknown device authorizations promptly to reduce exposure.
INSIGHT

Authorization Sprawl Enables Broad Cloud Access

  • The SalesLoft Drift breach exposed OAuth tokens that granted broad access across many cloud services.
  • Attackers exploited authorization sprawl instead of malware, highlighting risks in third-party integrations.
Get the Snipd Podcast app to discover more snips from this episode
Get the app