logo

Compromised Microsoft Key: More Impactful Than We Thought

ID: 22181219-dba9-5d4b-83f6-dea2b3f15daa

STIX ID: report--22181219-dba9-5d4b-83f6-dea2b3f15daa

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2023-07-21

Date Updated: 2026-05-01

...
...

This report examines the Storm-0558 incident in which a nation-state-linked actor acquired a Microsoft consumer identity signing private key (MSA), enabling offline forging of OpenID v2.0 tokens to impersonate users across Outlook/Exchange and potentially millions of Azure AD v2.0 applications; it describes the affected application types, forensic detection methods (including the compromised key kid and published IP IOCs), risks from cached/trusted keys and persistence, and recommends mitigations such as revoking keys, updating Azure SDKs, refreshing local certificate caches, and reviewing application logs for forged tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.