Security News > 2024 > July > Microsoft: DDoS defense error amplified attack on Azure, leading to outage
A DDoS attack that started on Tuesday has made a number of Microsoft Azure and Microsoft 365 services temporarily inaccessible, the company has confirmed.
Microsoft's mitigation statement on the Azure status history page.
Microsoft Azure, 365 outage triggered by DDoS. "Between approximately at 11:45 UTC and 19:43 UTC on 30 July 2024, a subset of customers may have experienced issues connecting to a subset of Microsoft services globally. Impacted services included Azure App Services, Application Insights, Azure IoT Central, Azure Log Search Alerts, Azure Policy, as well as the Azure portal itself and a subset of Microsoft 365 and Microsoft Purview services," Microsoft said.
"An unexpected usage spike resulted in Azure Front Door and Azure Content Delivery Network components performing below acceptable thresholds, leading to intermittent errors, timeout, and latency spikes."
Users were also unable to access some Microsoft 365 services - Microsoft 365 admin center, Intune, Entra and Power Platform - but SharePoint Online, OneDrive for Business, Microsoft Teams and Exchange Online remained accessible and responsive.
Microsoft said that the outage was triggered by a Distributed Denial-of-Service attack, and that its effect was amplified by an error in the implementation of Azure DDoS defenses.
News URL
https://www.helpnetsecurity.com/2024/07/31/microsoft-azure-ddos/
Related news
- Microsoft enforces defenses preventing NTLM relay attacks (source)
- Microsoft warns Azure Virtual Desktop users of black screen issues (source)
- VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware (source)
- Microsoft patches Windows zero-day exploited in attacks on Ukraine (source)
- Microsoft 365 outage impacts Exchange Online, Teams, Sharepoint (source)
- Microsoft Fixes AI, Cloud, and ERP Security Flaws; One Exploited in Active Attacks (source)
- Phishing-as-a-Service "Rockstar 2FA" Targets Microsoft 365 Users with AiTM Attacks (source)
- CERT-UA Warns of Phishing Attacks Targeting Ukraine’s Defense and Security Force (source)
- Microsoft 365 outage takes down Office web apps, admin center (source)
- Europol Dismantles 27 DDoS Attack Platforms Across 15 Nations; Admins Arrested (source)