April 3, 2024, 1:37 p.m. | Zeljka Zorz

Help Net Security www.helpnetsecurity.com

Microsoft still doesn’t known how Storm-0558 attackers managed to steal the Microsoft Services Account cryptographic key they used to forge authentication tokens needed to access email accounts belonging to US government officials. “The stolen 2016 MSA key in combination with [a] flaw in the token validation system permitted the threat actor to gain full access to essentially any Exchange Online account,” CISA’s Cyber Safety Review Board (CSRB) noted in a recently released Review of the … More →


The post …

access account accounts apt attackers authentication chinese chinese hackers cisa cloud security cryptographic csp don't miss email errors flaw forge government government-backed attacks hackers hot stuff key managed microsoft msa key officials services steal stolen storm storm-0558 system token tokens uk usa validation

More from www.helpnetsecurity.com / Help Net Security

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

COMM Penetration Tester (PenTest-2), Chantilly, VA OS&CI Job #368

@ Allen Integrated Solutions | Chantilly, Virginia, United States

Consultant Sécurité SI H/F Gouvernance - Risques - Conformité

@ Hifield | Sèvres, France

Infrastructure Consultant

@ Telefonica Tech | Belfast, United Kingdom