Microsoft still unsure how hackers stole MSA key in 2023 Exchange attack
ID: d527e725-3243-5f53-8434-bfe9ac3b1fe1
STIX ID: report--d527e725-3243-5f53-8434-bfe9ac3b1fe1
Feed Name: Bleeping Computer
The CSRB criticized Microsoft’s handling of the May 2023 Exchange Online espionage intrusion by Storm-0558, which leveraged forged authentication tokens signed with a 2016 MSA key to access email accounts of senior U.S. officials and others (over 500 individuals across 22 organizations and ~60,000 State Dept emails); Microsoft identified design and operational failures (manual key rotation, OIDC/SDK misconfiguration, limited logging) and has not produced conclusive evidence for how the key was exfiltrated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
