home.social

#storm0558 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #storm0558, aggregated by home.social.

fetched live
  1. The #CSRB report on the #Microsoft #Azure #Storm0558 security incident says that Cloud Service Providers (#CSP) should adopt a minimum standard for default audit logging.

    A wonder which standard exist there? Any pointers welcome.
    The report later mentions the #FedRAMP AU-2 "standard". But I couldn't find it 😠

    #CyberSecurity

  2. #Microsoft has been #pwned for two times in the last six month. Does it change anything?

    Ars Technica: Microsoft finally explains cause of Azure breach: An engineer’s account was hacked.

    Last year #Azure was pwned by #Storm-0558, „a china-based threat actor with activities and methods consistent with espionage objectives.“


    CNN: Russian hackers breached key Microsoft systems.

    And now they are still pwned by #CozyBear, „russian state-backed hackers“. Does anybody care about this?

    We really need to push forward our open source ressources.

    #opensource
  3. DHS Cyber Safety Review Board (CSRB) absolutely savages Microsoft over the June 2023 Exchange Online breach by Chinese threat actor Storm-0558 and accessing U.S. government emails right before Secretary of State Anthony Blinken was to visit China. This 34 page PDF is written in the style of a U.S. Government Accountability Office (GAO) report. 🔗 dhs.gov/news/2024/04/02/cyber-

    Key takeways (copied verbatim, emphasis mine):

    • "Google's Threat Analysis Group was able to link at least one entity tied to this threat actor to the group responsible for the 2009 compromise of Google and dozens of other private companies in a campaign known as Operation Aurora, as well as the RSA SecurID incident."
    • "However, by the conclusion of this review, Microsoft was still unable to demonstrate to the Board that it knew how Storm-0558 had obtained the 2016 MSA key."
    • "Microsoft acknowledged to the Board in November 2023 that its September 6, 2023 blog post about the root cause was inaccurate, it did not update that post until March 12, 2024, as the Board was concluding its review and only after the Board's repeated questioning about Microsoft's plans to issue a correction;"

    #DHS #CSRB #Microsoft #MSRC #China #cyberespionage #Storm0558

  4. Microsoft Security Response Center (MSRC) quietly updated their 06 September 2023 blog post about the Storm-0558 technical investigation on 12 March 2024 (6 months later) due to DHS Cyber Safety Review Board (CSRB) repeatedly asking them when they were going to update the inaccurate information. 🔗 msrc.microsoft.com/blog/2023/0

    First, what hasn’t changed:

    1. Our leading hypothesis remains that operational errors resulted in key material leaving the secure token signing environment that was subsequently accessed in a debugging environment via a compromised engineering account.
    2. There is no change in the customer or Microsoft impact or actor activity. Current information may still be found in our Microsoft Security Blog.

    Here are the key items which we are updating based on what we have learned since September 6, 2023:

    1. The blog below states that the actor access may have resulted from a crash dump in 2021, but we have not found a crash dump containing the impacted key material.
    2. The race condition mentioned in the blog below did not impact whether the key could be present in the crash dump, but rather whether the crash dump could be removed from the secure token signing environment.
    3. We indicated moving crash dump material out of the secure signing environment was consistent with standard debugging process – we intended to indicate that this was not prohibited in the past, and thus could have happened. Our standard debugging process at Microsoft prohibits removing such materials from the production environment today.
    4. Our ongoing investigations have revealed limitations in cred scanning technologies which we will address as we discover them.

    #Microsoft #China #cyberespionage #Storm0558

  5. Microsoft's lax security blasted by investigators after serious breach

    Cascade of failings allowed Chinese hackers to access government emails, says US review board

    computing.co.uk/news/4192192/m

    #infosec #microsoft #technews #csrb #storm0558

  6. I’m no expert, but (and this is a real question) why the fsck was sensitive key material floating around in RAM to begin with??! Isn’t this attack vector EXACTLY what an HSM is designed to defend against?

    What kind of “Zero-Trust and ‘assume breach’ mindset” allows signing keys to be handled:

    1) In software.
    2) Without formal verification.
    3) In a non-memory safe programming language.

    And why hadn’t that key been rotated AT LEAST since APRIL 2021?!

    This RCA is so full of self-owns and unforced errors it’s not even funny.

    msrc.microsoft.com/blog/2023/0

    @agreenberg @SwiftOnSecurity @lhn #Microsoft #hack #security #storm0558

  7. Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.

    How can you believe anything they say months later? This blogpost was written by lawyers and noone else.

    #signingkey #microsoft #storm0558 #ms #m365 #infosec

  8. Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!

    msrc.microsoft.com/blog/2023/0

    #ms #microsoft #Storm0558 #signingkey

  9. Microsoft released the findings of their investigation into how Storm-0558 managed to get hold of a signing key that have then access to customers email. Two points that jump out:

    1) Turns out even Microsoft can't afford the ingestion fees for Sentinel! 😜

    2) Let's also gloss over the fact the corporate network appears to be compromised 🙄

    Those two points aside hats off to them for this investigation, can't deny that's impressive work.
    msrc.microsoft.com/blog/2023/0

    #Microsoft #Storm0558

  10. The #Microsoft report on the technical investigations for #Storm0558 key acquisition is a rather interesting read.

    They of course can't and don't go into specifics about the nature of the key leakage. I'm totally guessing here, but it might be that the tooling Microsoft used to detect and sanitize the #keymaterial didn't identify the key in the specific key schedule form. Maybe a new #encryption cipher was used that uses a new key schedule format that the tooling didn't support, or the cipher implementation started to store the key schedule in a new, different way.

    This incident is a good example on how attempts of #sanitizing logs, memory dumps and similar of sensitive information are a losing game. At best it can be considered best effort, there's always ways information can end up leaking out despite your best efforts in trying to identify it.

    For critical systems the encryption key should only ever exists in a security enclave or HSM. That'd be the only way to ensure that the key cannot leak: It's nowhere in the memory to begin with.

    ref:
    msrc.microsoft.com/blog/2023/0

  11. Storm-0558 hacks of Microsoft Exchange

    In mid-July 2023, Microsoft reported that a Chinese hacking group tracked as '#Storm0558' breached the email accounts of 25 organizations, including US and Western European government agencies, using #forged #authentication #tokens from a stolen Microsoft consumer #signing #key.

    Using this stolen key, the Chinese threat actors exploited a zero-day vulnerability in the #GetAccessTokenForResource API function for Outlook Web Access in Exchange Online (#OWA) to forge authorization tokens.

    These tokens allowed the threat actors to impersonate Azure accounts and access email accounts for numerous government agencies and organizations to monitor and steal email.

    After these attacks, Microsoft faced a lot of criticism for not providing adequate #logging to Microsoft customers for free. Instead, Microsft required customers to purchase additional licenses to obtain logging data that could have helped detect these attacks.

    After working with CISA to identify crucial logging data needed to #detect #attacks, Microsoft announced that they now offer it for free to all Microsoft customers.

    c.im/@cdarwin/1108682528634912

  12. Did anybody hear anything from the Europeans, who were the primary victims of those chinese attackers #storm0558 with a stolen master key to the #microsoft cloud?
    Why are they so quiet about this?
    #cybersecurity #infosec #security

  13. Finally took some time to read the Wiz article regarding Storm-0558 in depth, and working on a blog post that dissects it all.

    While we all make mistakes, considering that Wiz knows they are a golden child, they really should do better.

    It's hard to not speculate that they spent zero time trying to understand how OpenID Connect and OAuth 2.0 function before authoring the article, based on how poorly written it is from an identity terminology perspective.

    #wiz #microsoft #entraid #Storm0558 #aad #entra #azuread #infosec

  14. The recent #Microsoft365 attack by China-based #apt #STORM0558 continues to gain coverage. Steven Adair spoke to Raphael Satter at Reuters about ways #Microsoft could empower customers & security companies so they can work together: reuters.com/technology/microso

    #dfir #threatintel

  15. Steven Adair spoke to Robert McMillan at The Wall Street Journal about the #Microsoft report detailing the recent attack on #Microsoft365 by a China-based #apt known as #STORM0558, sharing @volexity's experience and findings (or lack thereof): wsj.com/articles/china-hacking

    #dfir #threatintel