logo

Storm-0558 Update: Takeaways from Microsoft's recent report

ID: 4d993e9f-593f-579a-b1ad-d78711b48a2d

STIX ID: report--4d993e9f-593f-579a-b1ad-d78711b48a2d

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2023-09-07

Date Updated: 2026-05-01

...
...

Wiz Research reviews Microsoft’s report on Storm-0558, which likely acquired an MSA signing key from a crash dump on a corporate debugging server accessed via a compromised engineer account; this key enabled forged authentication tokens used to access Exchange and Outlook and potentially other services. The post details contributing factors (missing issuer validation in the Azure AD SDK and an Exchange validation bug), recommends mitigations (HSMs, regular key rotation, secret scanning, purging debug data, asset inventories and isolation), and lists outstanding questions about the timeline, breadth of access, and whether other keys or systems were compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.