Storm-0558 Update: Takeaways from Microsoft's recent report
ID: 4d993e9f-593f-579a-b1ad-d78711b48a2d
STIX ID: report--4d993e9f-593f-579a-b1ad-d78711b48a2d
Feed Name: Wiz Blog
Wiz Research reviews Microsoft’s report on Storm-0558, which likely acquired an MSA signing key from a crash dump on a corporate debugging server accessed via a compromised engineer account; this key enabled forged authentication tokens used to access Exchange and Outlook and potentially other services. The post details contributing factors (missing issuer validation in the Azure AD SDK and an Exchange validation bug), recommends mitigations (HSMs, regular key rotation, secret scanning, purging debug data, asset inventories and isolation), and lists outstanding questions about the timeline, breadth of access, and whether other keys or systems were compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
