ThreatPaper

Page 5 of 5

Earlier Research

Russian state-sponsored group Midnight Blizzard (APT29) breached Microsoft's corporate environment via password spray against a legacy non-production test tenant, accessed executive and security team email, and exfiltrated OAuth tokens and source code — demonstrating sophisticated identity-based tradecraft without malware.

State-SponsoredData Breach

Weekly Digest

New research, once a week. No vendor pitches.

About ThreatPaper

Structured, technical research on real high-impact cybercrime incidents. Not news. Not CVE feeds. Verified, cited, educational.

Learn more →