U.S. Cyber Safety Board Slams Microsoft Over Breach by China-Based Hackers
ID: 437a1fe0-0c65-59c8-adac-16ebc1053271
STIX ID: report--437a1fe0-0c65-59c8-adac-16ebc1053271
Feed Name: The Hacker News
Executive summary: The CSRB and DHS criticized Microsoft after Storm-0558 (a China-linked nation-state group) exploited a validation flaw and likely leaked signing key material to forge Azure AD tokens, accessing 22 organizations and over 500 consumer accounts and exfiltrating roughly 60,000 unclassified Outlook emails. The report attributes the breach to preventable operational and engineering failures at Microsoft, notes continued investigation, and recommends improved cloud identity controls, logging, key management and incident transparency.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
