Compromised Microsoft Key: More Impactful Than We Thought
ID: 22181219-dba9-5d4b-83f6-dea2b3f15daa
STIX ID: report--22181219-dba9-5d4b-83f6-dea2b3f15daa
Feed Name: Wiz Blog
This report examines the Storm-0558 incident in which a nation-state-linked actor acquired a Microsoft consumer identity signing private key (MSA), enabling offline forging of OpenID v2.0 tokens to impersonate users across Outlook/Exchange and potentially millions of Azure AD v2.0 applications; it describes the affected application types, forensic detection methods (including the compromised key kid and published IP IOCs), risks from cached/trusted keys and persistence, and recommends mitigations such as revoking keys, updating Azure SDKs, refreshing local certificate caches, and reviewing application logs for forged tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
