HomeSecurityMicrosoft: Stolen key offered access to cloud services

Microsoft: Stolen key provided access to cloud services

Microsoft's consumer signing key was stolen by Chinese hackers (Storm-0558). With this key, the hackers were able to access Exchange Online and Outlook.com accounts that the company previously said had been compromised, according to what security researchers at Wiz revealed.

See also: Microsoft Teams receives an important security update

Microsoft

Exchange Online technology has been widely adopted by small, medium and large businesses. It is a cloud-based email service that provides better security, reliability and scalability.

The company revealed on July 12 that attackers had compromised the Exchange Online and Azure Active Directory (AD) accounts of about a dozen organizations. This was done using a zero-day validation flaw, which has now been fixed in the GetAccessTokenForResourceAPI. This allowed them to forge signed access tokens and create fake accounts within the targeted organizations.

The affected authorities were government agencies in parts of the US and Western Europe, including the US Department of State and Commerce.

On Friday, Wiz security researcher Shir Tamari announced that the impact had affected all Azure AD applications that use Microsoft's OpenID v2.0. This was because the stolen key could be used to gain access to personal accounts (such as Xbox, Skype) and multi-tenant AAD applications via the OpenID v2.0 access token .

Microsoft clarified that the problem only affected those who had personal accounts and were experiencing a validation error.

See also: Bing Chat Enterprise: Microsoft brings chatbot for businesses

key

Although Microsoft says only Exchange Online and Outlook, Wiz explains that hackers can use the compromised Microsoft consumer signing key to impersonate any account on any affected Microsoft cloud-based client or application.

“This includes managed apps , such as Outlook, SharePoint, OneDrive, and Teams, as well as client apps that support Microsoft account authentication, including those that enable the “Sign in to Microsoft” feature,” Tamari said.

Microsoft revoked all valid MSA signing keys after the security breach, to ensure that the perpetrators cannot access other compromised zones.

This measure prevented the creation of any new access. In addition, the company reported on the new access credentials created in the key store for the company's corporate systems .

After the stolen signing key was revoked, Microsoft did not recover any other unauthorized access to its customers' accounts using the same technique.

Microsoft says it has noticed a change in Storm-0558's tactics, suggesting that the malicious actors no longer have access to any signing keys.

See also: Activision Blizzard franchises that will be owned by Microsoft

The company recently announced that it has yet to figure out how Chinese hackers managed to steal the signing key used by Microsoft consumers. However, after pressure from CISA, they have agreed to expand free access to cloud logging data to help defenders identify similar breach attempts in the future.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS