home.social

#wizresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #wizresearch, aggregated by home.social.

fetched live
  1. #Microsoft apparently denies the report from #WizResearch that the impact of the stolen keys from the #Microsoft365 #hack was more severe than what Microsoft initially reported in their #blog, calling it "speculative and not evidence-based".

    When asked for comments, Wiz Research was surprised at Microsoft's response because they said that their blog post was "reviewed and validated" by the Microsoft Security Research Team.

    #infosec #cybersecurity #cloudsecurity #Azure

    https://therecord.media/microsoft-disputes-report-on-chinese-hacking

  2. The implication of the #Microsoft365 #hack goes deeper than just affecting #ExchangeOnline. Researchers from #WizResearch notes that the implication of the stolen #MSA keys could have allowed the attacker to:

    forge access tokens for multiple types of Azure Active Directory applications, including every application that supports personal account authentication, such as SharePoint, Teams, OneDrive, customers’ applications that support the “login with Microsoft” functionality, and multi-tenant applications in certain conditions.
    #infosec #cybersecurity #databreach #dataloss #cloudsecurity

    https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr