3 ms·
Found following from the links from the post: 2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically al
by pritambarhate 3y ago
Found following from the links from the post:
2023-07: Hackers stole a Microsoft Azure Active Directory certificate which gave them full access to basically all Microsoft cloud services including Outlook, Office, SharePoint, Teams, "Login with Microsoft", and so forth. (MS blog entry [1], Source[2], German source)
Also the following:
https://infosec.exchange/@briankrebs/110820474957163710 https://infosec.exchange/@briankrebs/110820474957163710
Quite damning if true.
[1]: https://www.microsoft.com/en-us/security/blog/2023/07/14/analysis-of-storm-0558-techniques-for-unauthorized-email-access/ https://www.microsoft.com/en-us/security/blog/2023/07/14/ana...
[2]: https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr https://www.wiz.io/blog/storm-0558-compromised-microsoft-key...
- _23sd 3y agoThe issue was specific to services that used Microsoft's .NET libraries for Azure AD authentication without doing additional checks for auth token validity [1], which was not "all of Microsoft". There's no public list of what components are used where AFAIK, we just know that MS says forged auth tokens were successfully used on Exchange Online email. It is sensationalizing to say the entire Azure cloud was hacked. This is not to downplay how bad Microsoft's security lapses were, and how bad their announcements were. The most horrifying part to me, besides the need for "premium" logs to detect a breach which I'd been complaining about before this, was how PR seemed to blame the Exchange Online team for misusing the authentication libraries, but later they updated the libraries and said the token validation issue was "corrected using the updated libraries". That feels like internal blame shifting out in public. [1] https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/#why-a-consumer-key-was-able-to-access-enterprise-mail https://msrc.microsoft.com/blog/2023/09/results-of-major-tec...