#storm0558 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #storm0558, aggregated by home.social.
-
Gerade vom Kollegen rausgefischt
@LinksfraktionHH Datenschutz, digitale Souveränität und Kostenfragen beim Einsatz von Microsoft 365 in der Hamburger Verwaltung - 23/2931 Große Anfrage vom 29.01.2026: https://www.buergerschaft-hh.de/parldok/dokument/102664/23_02931_datenschutz_digitale_souveraenitaet_und_kostenfragen_beim_einsatz_von_microsoft_365_in_der_hamburger_verwaltung
(Parlamentsdatenbank: https://www.buergerschaft-hh.de/parldok/suche/10_1_23___23.%20Wahlperiode%20(ab%2026.03.2025)/7_1_1___Drucksache/9_1_29.01.2026_datefrom__Von%3A%2029.01.2026/8_1_2___Dokumenttyp%3A%20Gro%C3%9Fe%20Anfrage)
#hhbue #LinksfraktionHamburg #DieLinkeHamburg #Hamburg #DigitaleSouveränität #microsoft #Microsoft365 #ms365 #Storm0558 #FISA
-
Gerade vom Kollegen rausgefischt
@LinksfraktionHH Datenschutz, digitale Souveränität und Kostenfragen beim Einsatz von Microsoft 365 in der Hamburger Verwaltung - 23/2931 Große Anfrage vom 29.01.2026: https://www.buergerschaft-hh.de/parldok/dokument/102664/23_02931_datenschutz_digitale_souveraenitaet_und_kostenfragen_beim_einsatz_von_microsoft_365_in_der_hamburger_verwaltung
(Parlamentsdatenbank: https://www.buergerschaft-hh.de/parldok/suche/10_1_23___23.%20Wahlperiode%20(ab%2026.03.2025)/7_1_1___Drucksache/9_1_29.01.2026_datefrom__Von%3A%2029.01.2026/8_1_2___Dokumenttyp%3A%20Gro%C3%9Fe%20Anfrage)
#hhbue #LinksfraktionHamburg #DieLinkeHamburg #Hamburg #DigitaleSouveränität #microsoft #Microsoft365 #ms365 #Storm0558 #FISA
-
Gerade vom Kollegen rausgefischt
@LinksfraktionHH Datenschutz, digitale Souveränität und Kostenfragen beim Einsatz von Microsoft 365 in der Hamburger Verwaltung - 23/2931 Große Anfrage vom 29.01.2026: https://www.buergerschaft-hh.de/parldok/dokument/102664/23_02931_datenschutz_digitale_souveraenitaet_und_kostenfragen_beim_einsatz_von_microsoft_365_in_der_hamburger_verwaltung
(Parlamentsdatenbank: https://www.buergerschaft-hh.de/parldok/suche/10_1_23___23.%20Wahlperiode%20(ab%2026.03.2025)/7_1_1___Drucksache/9_1_29.01.2026_datefrom__Von%3A%2029.01.2026/8_1_2___Dokumenttyp%3A%20Gro%C3%9Fe%20Anfrage)
#hhbue #LinksfraktionHamburg #DieLinkeHamburg #Hamburg #DigitaleSouveränität #microsoft #Microsoft365 #ms365 #Storm0558 #FISA
-
Gerade vom Kollegen rausgefischt
@LinksfraktionHH Datenschutz, digitale Souveränität und Kostenfragen beim Einsatz von Microsoft 365 in der Hamburger Verwaltung - 23/2931 Große Anfrage vom 29.01.2026: https://www.buergerschaft-hh.de/parldok/dokument/102664/23_02931_datenschutz_digitale_souveraenitaet_und_kostenfragen_beim_einsatz_von_microsoft_365_in_der_hamburger_verwaltung
(Parlamentsdatenbank: https://www.buergerschaft-hh.de/parldok/suche/10_1_23___23.%20Wahlperiode%20(ab%2026.03.2025)/7_1_1___Drucksache/9_1_29.01.2026_datefrom__Von%3A%2029.01.2026/8_1_2___Dokumenttyp%3A%20Gro%C3%9Fe%20Anfrage)
#hhbue #LinksfraktionHamburg #DieLinkeHamburg #Hamburg #DigitaleSouveränität #microsoft #Microsoft365 #ms365 #Storm0558 #FISA
-
Gerade vom Kollegen rausgefischt
@LinksfraktionHH Datenschutz, digitale Souveränität und Kostenfragen beim Einsatz von Microsoft 365 in der Hamburger Verwaltung - 23/2931 Große Anfrage vom 29.01.2026: https://www.buergerschaft-hh.de/parldok/dokument/102664/23_02931_datenschutz_digitale_souveraenitaet_und_kostenfragen_beim_einsatz_von_microsoft_365_in_der_hamburger_verwaltung
(Parlamentsdatenbank: https://www.buergerschaft-hh.de/parldok/suche/10_1_23___23.%20Wahlperiode%20(ab%2026.03.2025)/7_1_1___Drucksache/9_1_29.01.2026_datefrom__Von%3A%2029.01.2026/8_1_2___Dokumenttyp%3A%20Gro%C3%9Fe%20Anfrage)
#hhbue #LinksfraktionHamburg #DieLinkeHamburg #Hamburg #DigitaleSouveränität #microsoft #Microsoft365 #ms365 #Storm0558 #FISA
-
The #CSRB report on the #Microsoft #Azure #Storm0558 security incident says that Cloud Service Providers (#CSP) should adopt a minimum standard for default audit logging.
A wonder which standard exist there? Any pointers welcome.
The report later mentions the #FedRAMP AU-2 "standard". But I couldn't find it 😠 -
The #CSRB report on the #Microsoft #Azure #Storm0558 security incident says that Cloud Service Providers (#CSP) should adopt a minimum standard for default audit logging.
A wonder which standard exist there? Any pointers welcome.
The report later mentions the #FedRAMP AU-2 "standard". But I couldn't find it 😠 -
The #CSRB report on the #Microsoft #Azure #Storm0558 security incident says that Cloud Service Providers (#CSP) should adopt a minimum standard for default audit logging.
A wonder which standard exist there? Any pointers welcome.
The report later mentions the #FedRAMP AU-2 "standard". But I couldn't find it 😠 -
The #CSRB report on the #Microsoft #Azure #Storm0558 security incident says that Cloud Service Providers (#CSP) should adopt a minimum standard for default audit logging.
A wonder which standard exist there? Any pointers welcome.
The report later mentions the #FedRAMP AU-2 "standard". But I couldn't find it 😠 -
The #CSRB report on the #Microsoft #Azure #Storm0558 security incident says that Cloud Service Providers (#CSP) should adopt a minimum standard for default audit logging.
A wonder which standard exist there? Any pointers welcome.
The report later mentions the #FedRAMP AU-2 "standard". But I couldn't find it 😠 -
DHS Cyber Safety Review Board (CSRB) absolutely savages Microsoft over the June 2023 Exchange Online breach by Chinese threat actor Storm-0558 and accessing U.S. government emails right before Secretary of State Anthony Blinken was to visit China. This 34 page PDF is written in the style of a U.S. Government Accountability Office (GAO) report. 🔗 https://www.dhs.gov/news/2024/04/02/cyber-safety-review-board-releases-report-microsoft-online-exchange-incident-summer
Key takeways (copied verbatim, emphasis mine):
- "Google's Threat Analysis Group was able to link at least one entity tied to this threat actor to the group responsible for the 2009 compromise of Google and dozens of other private companies in a campaign known as Operation Aurora, as well as the RSA SecurID incident."
- "However, by the conclusion of this review, Microsoft was still unable to demonstrate to the Board that it knew how Storm-0558 had obtained the 2016 MSA key."
- "Microsoft acknowledged to the Board in November 2023 that its September 6, 2023 blog post about the root cause was inaccurate, it did not update that post until March 12, 2024, as the Board was concluding its review and only after the Board's repeated questioning about Microsoft's plans to issue a correction;"
#DHS #CSRB #Microsoft #MSRC #China #cyberespionage #Storm0558
-
DHS Cyber Safety Review Board (CSRB) absolutely savages Microsoft over the June 2023 Exchange Online breach by Chinese threat actor Storm-0558 and accessing U.S. government emails right before Secretary of State Anthony Blinken was to visit China. This 34 page PDF is written in the style of a U.S. Government Accountability Office (GAO) report. 🔗 https://www.dhs.gov/news/2024/04/02/cyber-safety-review-board-releases-report-microsoft-online-exchange-incident-summer
Key takeways (copied verbatim, emphasis mine):
- "Google's Threat Analysis Group was able to link at least one entity tied to this threat actor to the group responsible for the 2009 compromise of Google and dozens of other private companies in a campaign known as Operation Aurora, as well as the RSA SecurID incident."
- "However, by the conclusion of this review, Microsoft was still unable to demonstrate to the Board that it knew how Storm-0558 had obtained the 2016 MSA key."
- "Microsoft acknowledged to the Board in November 2023 that its September 6, 2023 blog post about the root cause was inaccurate, it did not update that post until March 12, 2024, as the Board was concluding its review and only after the Board's repeated questioning about Microsoft's plans to issue a correction;"
#DHS #CSRB #Microsoft #MSRC #China #cyberespionage #Storm0558
-
DHS Cyber Safety Review Board (CSRB) absolutely savages Microsoft over the June 2023 Exchange Online breach by Chinese threat actor Storm-0558 and accessing U.S. government emails right before Secretary of State Anthony Blinken was to visit China. This 34 page PDF is written in the style of a U.S. Government Accountability Office (GAO) report. 🔗 https://www.dhs.gov/news/2024/04/02/cyber-safety-review-board-releases-report-microsoft-online-exchange-incident-summer
Key takeways (copied verbatim, emphasis mine):
- "Google's Threat Analysis Group was able to link at least one entity tied to this threat actor to the group responsible for the 2009 compromise of Google and dozens of other private companies in a campaign known as Operation Aurora, as well as the RSA SecurID incident."
- "However, by the conclusion of this review, Microsoft was still unable to demonstrate to the Board that it knew how Storm-0558 had obtained the 2016 MSA key."
- "Microsoft acknowledged to the Board in November 2023 that its September 6, 2023 blog post about the root cause was inaccurate, it did not update that post until March 12, 2024, as the Board was concluding its review and only after the Board's repeated questioning about Microsoft's plans to issue a correction;"
#DHS #CSRB #Microsoft #MSRC #China #cyberespionage #Storm0558
-
DHS Cyber Safety Review Board (CSRB) absolutely savages Microsoft over the June 2023 Exchange Online breach by Chinese threat actor Storm-0558 and accessing U.S. government emails right before Secretary of State Anthony Blinken was to visit China. This 34 page PDF is written in the style of a U.S. Government Accountability Office (GAO) report. 🔗 https://www.dhs.gov/news/2024/04/02/cyber-safety-review-board-releases-report-microsoft-online-exchange-incident-summer
Key takeways (copied verbatim, emphasis mine):
- "Google's Threat Analysis Group was able to link at least one entity tied to this threat actor to the group responsible for the 2009 compromise of Google and dozens of other private companies in a campaign known as Operation Aurora, as well as the RSA SecurID incident."
- "However, by the conclusion of this review, Microsoft was still unable to demonstrate to the Board that it knew how Storm-0558 had obtained the 2016 MSA key."
- "Microsoft acknowledged to the Board in November 2023 that its September 6, 2023 blog post about the root cause was inaccurate, it did not update that post until March 12, 2024, as the Board was concluding its review and only after the Board's repeated questioning about Microsoft's plans to issue a correction;"
#DHS #CSRB #Microsoft #MSRC #China #cyberespionage #Storm0558
-
DHS Cyber Safety Review Board (CSRB) absolutely savages Microsoft over the June 2023 Exchange Online breach by Chinese threat actor Storm-0558 and accessing U.S. government emails right before Secretary of State Anthony Blinken was to visit China. This 34 page PDF is written in the style of a U.S. Government Accountability Office (GAO) report. 🔗 https://www.dhs.gov/news/2024/04/02/cyber-safety-review-board-releases-report-microsoft-online-exchange-incident-summer
Key takeways (copied verbatim, emphasis mine):
- "Google's Threat Analysis Group was able to link at least one entity tied to this threat actor to the group responsible for the 2009 compromise of Google and dozens of other private companies in a campaign known as Operation Aurora, as well as the RSA SecurID incident."
- "However, by the conclusion of this review, Microsoft was still unable to demonstrate to the Board that it knew how Storm-0558 had obtained the 2016 MSA key."
- "Microsoft acknowledged to the Board in November 2023 that its September 6, 2023 blog post about the root cause was inaccurate, it did not update that post until March 12, 2024, as the Board was concluding its review and only after the Board's repeated questioning about Microsoft's plans to issue a correction;"
#DHS #CSRB #Microsoft #MSRC #China #cyberespionage #Storm0558
-
Microsoft Security Response Center (MSRC) quietly updated their 06 September 2023 blog post about the Storm-0558 technical investigation on 12 March 2024 (6 months later) due to DHS Cyber Safety Review Board (CSRB) repeatedly asking them when they were going to update the inaccurate information. 🔗 https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/
First, what hasn’t changed:
- Our leading hypothesis remains that operational errors resulted in key material leaving the secure token signing environment that was subsequently accessed in a debugging environment via a compromised engineering account.
- There is no change in the customer or Microsoft impact or actor activity. Current information may still be found in our Microsoft Security Blog.
Here are the key items which we are updating based on what we have learned since September 6, 2023:
- The blog below states that the actor access may have resulted from a crash dump in 2021, but we have not found a crash dump containing the impacted key material.
- The race condition mentioned in the blog below did not impact whether the key could be present in the crash dump, but rather whether the crash dump could be removed from the secure token signing environment.
- We indicated moving crash dump material out of the secure signing environment was consistent with standard debugging process – we intended to indicate that this was not prohibited in the past, and thus could have happened. Our standard debugging process at Microsoft prohibits removing such materials from the production environment today.
- Our ongoing investigations have revealed limitations in cred scanning technologies which we will address as we discover them.
-
Microsoft Security Response Center (MSRC) quietly updated their 06 September 2023 blog post about the Storm-0558 technical investigation on 12 March 2024 (6 months later) due to DHS Cyber Safety Review Board (CSRB) repeatedly asking them when they were going to update the inaccurate information. 🔗 https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/
First, what hasn’t changed:
- Our leading hypothesis remains that operational errors resulted in key material leaving the secure token signing environment that was subsequently accessed in a debugging environment via a compromised engineering account.
- There is no change in the customer or Microsoft impact or actor activity. Current information may still be found in our Microsoft Security Blog.
Here are the key items which we are updating based on what we have learned since September 6, 2023:
- The blog below states that the actor access may have resulted from a crash dump in 2021, but we have not found a crash dump containing the impacted key material.
- The race condition mentioned in the blog below did not impact whether the key could be present in the crash dump, but rather whether the crash dump could be removed from the secure token signing environment.
- We indicated moving crash dump material out of the secure signing environment was consistent with standard debugging process – we intended to indicate that this was not prohibited in the past, and thus could have happened. Our standard debugging process at Microsoft prohibits removing such materials from the production environment today.
- Our ongoing investigations have revealed limitations in cred scanning technologies which we will address as we discover them.
-
Microsoft Security Response Center (MSRC) quietly updated their 06 September 2023 blog post about the Storm-0558 technical investigation on 12 March 2024 (6 months later) due to DHS Cyber Safety Review Board (CSRB) repeatedly asking them when they were going to update the inaccurate information. 🔗 https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/
First, what hasn’t changed:
- Our leading hypothesis remains that operational errors resulted in key material leaving the secure token signing environment that was subsequently accessed in a debugging environment via a compromised engineering account.
- There is no change in the customer or Microsoft impact or actor activity. Current information may still be found in our Microsoft Security Blog.
Here are the key items which we are updating based on what we have learned since September 6, 2023:
- The blog below states that the actor access may have resulted from a crash dump in 2021, but we have not found a crash dump containing the impacted key material.
- The race condition mentioned in the blog below did not impact whether the key could be present in the crash dump, but rather whether the crash dump could be removed from the secure token signing environment.
- We indicated moving crash dump material out of the secure signing environment was consistent with standard debugging process – we intended to indicate that this was not prohibited in the past, and thus could have happened. Our standard debugging process at Microsoft prohibits removing such materials from the production environment today.
- Our ongoing investigations have revealed limitations in cred scanning technologies which we will address as we discover them.
-
Microsoft Security Response Center (MSRC) quietly updated their 06 September 2023 blog post about the Storm-0558 technical investigation on 12 March 2024 (6 months later) due to DHS Cyber Safety Review Board (CSRB) repeatedly asking them when they were going to update the inaccurate information. 🔗 https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/
First, what hasn’t changed:
- Our leading hypothesis remains that operational errors resulted in key material leaving the secure token signing environment that was subsequently accessed in a debugging environment via a compromised engineering account.
- There is no change in the customer or Microsoft impact or actor activity. Current information may still be found in our Microsoft Security Blog.
Here are the key items which we are updating based on what we have learned since September 6, 2023:
- The blog below states that the actor access may have resulted from a crash dump in 2021, but we have not found a crash dump containing the impacted key material.
- The race condition mentioned in the blog below did not impact whether the key could be present in the crash dump, but rather whether the crash dump could be removed from the secure token signing environment.
- We indicated moving crash dump material out of the secure signing environment was consistent with standard debugging process – we intended to indicate that this was not prohibited in the past, and thus could have happened. Our standard debugging process at Microsoft prohibits removing such materials from the production environment today.
- Our ongoing investigations have revealed limitations in cred scanning technologies which we will address as we discover them.
-
Microsoft Security Response Center (MSRC) quietly updated their 06 September 2023 blog post about the Storm-0558 technical investigation on 12 March 2024 (6 months later) due to DHS Cyber Safety Review Board (CSRB) repeatedly asking them when they were going to update the inaccurate information. 🔗 https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/
First, what hasn’t changed:
- Our leading hypothesis remains that operational errors resulted in key material leaving the secure token signing environment that was subsequently accessed in a debugging environment via a compromised engineering account.
- There is no change in the customer or Microsoft impact or actor activity. Current information may still be found in our Microsoft Security Blog.
Here are the key items which we are updating based on what we have learned since September 6, 2023:
- The blog below states that the actor access may have resulted from a crash dump in 2021, but we have not found a crash dump containing the impacted key material.
- The race condition mentioned in the blog below did not impact whether the key could be present in the crash dump, but rather whether the crash dump could be removed from the secure token signing environment.
- We indicated moving crash dump material out of the secure signing environment was consistent with standard debugging process – we intended to indicate that this was not prohibited in the past, and thus could have happened. Our standard debugging process at Microsoft prohibits removing such materials from the production environment today.
- Our ongoing investigations have revealed limitations in cred scanning technologies which we will address as we discover them.
-
Microsoft's lax security blasted by investigators after serious breach
Cascade of failings allowed Chinese hackers to access government emails, says US review board
https://www.computing.co.uk/news/4192192/microsofts-lax-security-blasted-investigators-breach
-
Microsoft's lax security blasted by investigators after serious breach
Cascade of failings allowed Chinese hackers to access government emails, says US review board
https://www.computing.co.uk/news/4192192/microsofts-lax-security-blasted-investigators-breach
-
Microsoft's lax security blasted by investigators after serious breach
Cascade of failings allowed Chinese hackers to access government emails, says US review board
https://www.computing.co.uk/news/4192192/microsofts-lax-security-blasted-investigators-breach
-
Microsoft's lax security blasted by investigators after serious breach
Cascade of failings allowed Chinese hackers to access government emails, says US review board
https://www.computing.co.uk/news/4192192/microsofts-lax-security-blasted-investigators-breach
-
Microsoft's lax security blasted by investigators after serious breach
Cascade of failings allowed Chinese hackers to access government emails, says US review board
https://www.computing.co.uk/news/4192192/microsofts-lax-security-blasted-investigators-breach
-
I’m no expert, but (and this is a real question) why the fsck was sensitive key material floating around in RAM to begin with??! Isn’t this attack vector EXACTLY what an HSM is designed to defend against?
What kind of “Zero-Trust and ‘assume breach’ mindset” allows signing keys to be handled:
1) In software.
2) Without formal verification.
3) In a non-memory safe programming language.And why hadn’t that key been rotated AT LEAST since APRIL 2021?!
This RCA is so full of self-owns and unforced errors it’s not even funny.
@agreenberg @SwiftOnSecurity @lhn #Microsoft #hack #security #storm0558
-
I’m no expert, but (and this is a real question) why the fsck was sensitive key material floating around in RAM to begin with??! Isn’t this attack vector EXACTLY what an HSM is designed to defend against?
What kind of “Zero-Trust and ‘assume breach’ mindset” allows signing keys to be handled:
1) In software.
2) Without formal verification.
3) In a non-memory safe programming language.And why hadn’t that key been rotated AT LEAST since APRIL 2021?!
This RCA is so full of self-owns and unforced errors it’s not even funny.
@agreenberg @SwiftOnSecurity @lhn #Microsoft #hack #security #storm0558
-
I’m no expert, but (and this is a real question) why the fsck was sensitive key material floating around in RAM to begin with??! Isn’t this attack vector EXACTLY what an HSM is designed to defend against?
What kind of “Zero-Trust and ‘assume breach’ mindset” allows signing keys to be handled:
1) In software.
2) Without formal verification.
3) In a non-memory safe programming language.And why hadn’t that key been rotated AT LEAST since APRIL 2021?!
This RCA is so full of self-owns and unforced errors it’s not even funny.
@agreenberg @SwiftOnSecurity @lhn #Microsoft #hack #security #storm0558
-
I’m no expert, but (and this is a real question) why the fsck was sensitive key material floating around in RAM to begin with??! Isn’t this attack vector EXACTLY what an HSM is designed to defend against?
What kind of “Zero-Trust and ‘assume breach’ mindset” allows signing keys to be handled:
1) In software.
2) Without formal verification.
3) In a non-memory safe programming language.And why hadn’t that key been rotated AT LEAST since APRIL 2021?!
This RCA is so full of self-owns and unforced errors it’s not even funny.
@agreenberg @SwiftOnSecurity @lhn #Microsoft #hack #security #storm0558
-
Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.
How can you believe anything they say months later? This blogpost was written by lawyers and noone else.
-
Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.
How can you believe anything they say months later? This blogpost was written by lawyers and noone else.
-
Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.
How can you believe anything they say months later? This blogpost was written by lawyers and noone else.
-
Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.
How can you believe anything they say months later? This blogpost was written by lawyers and noone else.
-
Every single news source and comment I read accepts #Microsoft 's blogpost about the "stolen" signing key as truth.
How can you believe anything they say months later? This blogpost was written by lawyers and noone else.
-
Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!
-
Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!
-
Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!
-
Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!
-
Wow, I can't imagine how much overtime the Microsoft legal department had to work for this blog post on the signing key. They are the real heroes here!
-
Microsoft released the findings of their investigation into how Storm-0558 managed to get hold of a signing key that have then access to customers email. Two points that jump out:
1) Turns out even Microsoft can't afford the ingestion fees for Sentinel! 😜
2) Let's also gloss over the fact the corporate network appears to be compromised 🙄
Those two points aside hats off to them for this investigation, can't deny that's impressive work.
https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ -
Microsoft released the findings of their investigation into how Storm-0558 managed to get hold of a signing key that have then access to customers email. Two points that jump out:
1) Turns out even Microsoft can't afford the ingestion fees for Sentinel! 😜
2) Let's also gloss over the fact the corporate network appears to be compromised 🙄
Those two points aside hats off to them for this investigation, can't deny that's impressive work.
https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ -
Microsoft released the findings of their investigation into how Storm-0558 managed to get hold of a signing key that have then access to customers email. Two points that jump out:
1) Turns out even Microsoft can't afford the ingestion fees for Sentinel! 😜
2) Let's also gloss over the fact the corporate network appears to be compromised 🙄
Those two points aside hats off to them for this investigation, can't deny that's impressive work.
https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ -
Microsoft released the findings of their investigation into how Storm-0558 managed to get hold of a signing key that have then access to customers email. Two points that jump out:
1) Turns out even Microsoft can't afford the ingestion fees for Sentinel! 😜
2) Let's also gloss over the fact the corporate network appears to be compromised 🙄
Those two points aside hats off to them for this investigation, can't deny that's impressive work.
https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ -
Microsoft released the findings of their investigation into how Storm-0558 managed to get hold of a signing key that have then access to customers email. Two points that jump out:
1) Turns out even Microsoft can't afford the ingestion fees for Sentinel! 😜
2) Let's also gloss over the fact the corporate network appears to be compromised 🙄
Those two points aside hats off to them for this investigation, can't deny that's impressive work.
https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/ -
The #Microsoft report on the technical investigations for #Storm0558 key acquisition is a rather interesting read.
They of course can't and don't go into specifics about the nature of the key leakage. I'm totally guessing here, but it might be that the tooling Microsoft used to detect and sanitize the #keymaterial didn't identify the key in the specific key schedule form. Maybe a new #encryption cipher was used that uses a new key schedule format that the tooling didn't support, or the cipher implementation started to store the key schedule in a new, different way.
This incident is a good example on how attempts of #sanitizing logs, memory dumps and similar of sensitive information are a losing game. At best it can be considered best effort, there's always ways information can end up leaking out despite your best efforts in trying to identify it.
For critical systems the encryption key should only ever exists in a security enclave or HSM. That'd be the only way to ensure that the key cannot leak: It's nowhere in the memory to begin with.
-
The #Microsoft report on the technical investigations for #Storm0558 key acquisition is a rather interesting read.
They of course can't and don't go into specifics about the nature of the key leakage. I'm totally guessing here, but it might be that the tooling Microsoft used to detect and sanitize the #keymaterial didn't identify the key in the specific key schedule form. Maybe a new #encryption cipher was used that uses a new key schedule format that the tooling didn't support, or the cipher implementation started to store the key schedule in a new, different way.
This incident is a good example on how attempts of #sanitizing logs, memory dumps and similar of sensitive information are a losing game. At best it can be considered best effort, there's always ways information can end up leaking out despite your best efforts in trying to identify it.
For critical systems the encryption key should only ever exists in a security enclave or HSM. That'd be the only way to ensure that the key cannot leak: It's nowhere in the memory to begin with.
-
The #Microsoft report on the technical investigations for #Storm0558 key acquisition is a rather interesting read.
They of course can't and don't go into specifics about the nature of the key leakage. I'm totally guessing here, but it might be that the tooling Microsoft used to detect and sanitize the #keymaterial didn't identify the key in the specific key schedule form. Maybe a new #encryption cipher was used that uses a new key schedule format that the tooling didn't support, or the cipher implementation started to store the key schedule in a new, different way.
This incident is a good example on how attempts of #sanitizing logs, memory dumps and similar of sensitive information are a losing game. At best it can be considered best effort, there's always ways information can end up leaking out despite your best efforts in trying to identify it.
For critical systems the encryption key should only ever exists in a security enclave or HSM. That'd be the only way to ensure that the key cannot leak: It's nowhere in the memory to begin with.
-
The #Microsoft report on the technical investigations for #Storm0558 key acquisition is a rather interesting read.
They of course can't and don't go into specifics about the nature of the key leakage. I'm totally guessing here, but it might be that the tooling Microsoft used to detect and sanitize the #keymaterial didn't identify the key in the specific key schedule form. Maybe a new #encryption cipher was used that uses a new key schedule format that the tooling didn't support, or the cipher implementation started to store the key schedule in a new, different way.
This incident is a good example on how attempts of #sanitizing logs, memory dumps and similar of sensitive information are a losing game. At best it can be considered best effort, there's always ways information can end up leaking out despite your best efforts in trying to identify it.
For critical systems the encryption key should only ever exists in a security enclave or HSM. That'd be the only way to ensure that the key cannot leak: It's nowhere in the memory to begin with.
-
The #Microsoft report on the technical investigations for #Storm0558 key acquisition is a rather interesting read.
They of course can't and don't go into specifics about the nature of the key leakage. I'm totally guessing here, but it might be that the tooling Microsoft used to detect and sanitize the #keymaterial didn't identify the key in the specific key schedule form. Maybe a new #encryption cipher was used that uses a new key schedule format that the tooling didn't support, or the cipher implementation started to store the key schedule in a new, different way.
This incident is a good example on how attempts of #sanitizing logs, memory dumps and similar of sensitive information are a losing game. At best it can be considered best effort, there's always ways information can end up leaking out despite your best efforts in trying to identify it.
For critical systems the encryption key should only ever exists in a security enclave or HSM. That'd be the only way to ensure that the key cannot leak: It's nowhere in the memory to begin with.
-
Impressive writeup by my colleague Alexander Culafi on mounting #cybersecurity criticism about #Microsoft in the wake of the #Storm0558 attack.
https://www.techtarget.com/searchsecurity/news/366549116/Vendors-criticize-Microsoft-for-repeated-security-failings -
Impressive writeup by my colleague Alexander Culafi on mounting #cybersecurity criticism about #Microsoft in the wake of the #Storm0558 attack.
https://www.techtarget.com/searchsecurity/news/366549116/Vendors-criticize-Microsoft-for-repeated-security-failings -
Impressive writeup by my colleague Alexander Culafi on mounting #cybersecurity criticism about #Microsoft in the wake of the #Storm0558 attack.
https://www.techtarget.com/searchsecurity/news/366549116/Vendors-criticize-Microsoft-for-repeated-security-failings -
Impressive writeup by my colleague Alexander Culafi on mounting #cybersecurity criticism about #Microsoft in the wake of the #Storm0558 attack.
https://www.techtarget.com/searchsecurity/news/366549116/Vendors-criticize-Microsoft-for-repeated-security-failings -
Impressive writeup by my colleague Alexander Culafi on mounting #cybersecurity criticism about #Microsoft in the wake of the #Storm0558 attack.
https://www.techtarget.com/searchsecurity/news/366549116/Vendors-criticize-Microsoft-for-repeated-security-failings -
#Microsofts analysis of #Storm0558 techniques for unauthorized email access #office365 #microsoft365 #infosec