• My Account
  • Shop
  • Cart

Cyber Bunee

  • Home
  • News
    • artificial intelligence
    • cyber-security
    • hacking attacks
    • software dev
    • automation
    • certifications
    • Videos
      • Youtube Videos
    • Resources

    “Chinese Nation-State Actor Expands Attack on Microsoft’s Email Infrastructure: Insights and Recommendations”

    bunee 21 Jul 2023

    h1: Chinese Nation-State Actor Expands Scope of Attack on Microsoft’s Email Infrastructure

    h2: Key Details

    – Microsoft’s email infrastructure recently targeted by a Chinese nation-state actor known as Storm-0558.
    – The attack has a broader scope than initially believed.
    – Cloud security company Wiz reveals important information about the attack.

    h2: Extended Scope of the Attack

    – The attack involved using an inactive Microsoft account (MSA) consumer signing key.
    – The key was used to forge Azure Active Directory (Azure AD or AAD) tokens.
    – Illicit access to Outlook Web Access (OWA) and other Microsoft services was gained through the forged tokens.
    – The attackers could perform various malicious actions, such as reading users’ emails and accessing sensitive information.

    h2: Wiz’s Findings

    – Wiz explains how the attackers leveraged a chain of vulnerabilities to achieve their goals.
    – The initial vulnerability exploited was a weak implementation of a cryptographic function called “HSM signing function” in MSA.
    – The exploited vulnerability allowed the attackers to obtain the private keys for MSA.
    – With the private keys, the attackers could forge Azure AD tokens and gain access to OWA and other Microsoft services.

    h2: Implications and Recommendations

    – The broad scope of this attack highlights the importance of robust security measures for email infrastructure.
    – Users and organizations should ensure they have strong passwords, enable multi-factor authentication, and regularly update their software.
    – Microsoft has since taken steps to mitigate the attack and has invalidated the affected MSA keys.

    h2: Summary

    In a recent attack on Microsoft’s email infrastructure, a Chinese nation-state actor known as Storm-0558 demonstrated a broader scope than initially believed. Cloud security company Wiz provides important insights into the attack, revealing that the perpetrators used an inactive Microsoft account (MSA) consumer signing key to forge Azure Active Directory (Azure AD or AAD) tokens. With these tokens, they gained illicit access to Outlook Web Access (OWA) and other Microsoft services. Wiz explains that the attackers exploited vulnerabilities in the MSA implementation, allowing them to obtain private keys and forge the tokens. This attack serves as a reminder of the importance of robust security measures for email infrastructure, such as strong passwords and multi-factor authentication. Microsoft has taken steps to mitigate the attack, invalidating the affected MSA keys. Stay vigilant and keep your email security strong!

    Original Article: https://thehackernews.com/2023/07/azure-ad-token-forging-technique-in.html




    2023-07-21
    Facebook Twitter linkedin Pinterest WhatsAppt Telegram Email More
    Previous Article :

    Beware of HotRat: A Dangerous New Variant of Malware Disguised in Pirated Software

    Next Article :

    Apple May Stop Offering iMessage and FaceTime in the U.K.: Taking a Stand Against Surveillance Powers

    Similiar

    Unveiling Okta’s 2023 Support System Breach: Impact and Insights

    Unveiling Okta’s 2023 Support System Breach: Impact and Insights

    “Unmasking DJVU: The Ransomware Strain Hiding in Cracked Software”

    “Unmasking DJVU: The Ransomware Strain Hiding in Cracked Software”

    “Unmasking the Apache ActiveMQ Security Flaw: An In-depth Analysis of GoTitan and PrCtrl Rat Exploits”

    “Unmasking the Apache ActiveMQ Security Flaw: An In-depth Analysis of GoTitan and PrCtrl Rat Exploits”

    Leave a Reply Cancel reply

    Your email address will not be published. Required fields are marked *

    See Also...

    Unveiling Okta’s 2023 Support System Breach: Impact and Insights

    Unveiling Okta’s 2023 Support System Breach: Impact and Insights

    Okta Unveils More Details on 2023 Support System Breach Main Points: Okta, the identity services ...

    Latest News

    Innovating in Real Estate: Technology Landlords Can Use to Increase Profits and Make Management Easier
    news

    Innovating in Real Estate: Technology Landlords Can Use to Increase Profits and Make Management Easier

    bunee 02 Oct 2023
    And We’re Back!…
    news

    And We’re Back!…

    bunee 04 Jun 2023

    Tech Reviews

    Artificial Intelligence Takes Over Journalism: The Rise and Implications of AI-Generated Content in the Digital Age
    tech review

    Artificial Intelligence Takes Over Journalism: The Rise and Implications of AI-Generated Content in the Digital Age

    bunee 20 Jun 2023
    Tips and Gear to Stay Cool This Summer: Beat the Heat with These Simple Hacks
    tech review

    Tips and Gear to Stay Cool This Summer: Beat the Heat with These Simple Hacks

    bunee 20 Jun 2023
    The Importance of Technology Training for Government Employees
    tech review

    The Importance of Technology Training for Government Employees

    bunee 20 Jun 2023
    Choosing the Right Apple Laptop: A Guide for Budget and Professional Users
    tech review

    Choosing the Right Apple Laptop: A Guide for Budget and Professional Users

    bunee 20 Jun 2023
    “Oppenheimer Director Says AI is No More Dangerous Than Any Other Technology, but his New Movie Will Still Leave You Terrified”
    tech review

    “Oppenheimer Director Says AI is No More Dangerous Than Any Other Technology, but his New Movie Will Still Leave You Terrified”

    bunee 20 Jun 2023
    “US Counties Struggle with Severe Ob-Gyn Shortage: Post-Roe Laws Undermining Training Opportunities”
    tech review

    “US Counties Struggle with Severe Ob-Gyn Shortage: Post-Roe Laws Undermining Training Opportunities”

    bunee 20 Jun 2023
    Google’s Android Slate: The Ultimate Entertainment Hub and Smart Home Controller
    tech review

    Google’s Android Slate: The Ultimate Entertainment Hub and Smart Home Controller

    bunee 20 Jun 2023
    • Home
    • News
      • artificial intelligence
      • cyber-security
      • hacking attacks
      • software dev
      • automation
      • certifications
    • Videos
      • Youtube Videos
    • Resources

    Follow Us

    Popular Videos

    Newsletter

    Popular News

    • 1

      And We’re Back!…

    • 2

      New Magecart Campaign: Multiple Cybercrime Groups Operating Simultaneously

    • 3

      Major UK Organizations Suffer Data Breaches: Boots, British Airways, and the BBC Among Those Affected

    • 4

      Verizon Report: Human Error a Top Cause of Cybersecurity Incidents in 2019

    • 5

      Tech Firm Mitigates Ransomware Attack: Tips for Protection

    Fellow Sponsors

    Tags

    attacks break into cyber coinbase crypto hacking how to ransomware real estate technology updates
    (▀̿Ĺ̯▀̿ ̿) Copyright , All Rights Reserved
    Website courtesy of Lucid Perspective